ATT&CKReferencesKandji Cuckoo April 2024

Kandji Cuckoo April 2024

Kohler, A. and Lopez, C. (2024, April 30). Malware: Cuckoo Behaves Like Cross Between Infostealer and Spyware. Retrieved August 20, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples26

TechniqueUsed byProcedure example
T1027.008
Stripped Payloads
MalwareCuckoo Stealer

Cuckoo Stealer is a stripped binary payload.

T1027.013
Encrypted/Encoded File
MalwareCuckoo Stealer

Cuckoo Stealer strings are XOR-encrypted.

T1033
System Owner/User Discovery
MalwareCuckoo Stealer

Cuckoo Stealer can discover and send the username from a compromised host to C2.

T1036.005
Match Legitimate Resource Name or Location
MalwareCuckoo Stealer

Cuckoo Stealer has copied and renamed itself to DumpMediaSpotifyMusicConverter.

T1041
Exfiltration Over C2 Channel
MalwareCuckoo Stealer

Cuckoo Stealer can send information about the targeted system to C2 including captured passwords, OS build, hostname, and username.

T1056.002
GUI Input Capture
MalwareCuckoo Stealer

Cuckoo Stealer has captured passwords by prompting victims with a “macOS needs to access System Settings” GUI window.

T1057
Process Discovery
MalwareCuckoo Stealer

Cuckoo Stealer can use `ps aux` to enumerate running processes.

T1059.002
AppleScript
MalwareCuckoo Stealer

Cuckoo Stealer can use osascript to generate a password-stealing prompt, duplicate files and folders, and set environmental variables.

T1059.004
Unix Shell
MalwareCuckoo Stealer

Cuckoo Stealer can spawn a bash shell to enable execution on compromised hosts.

T1071.001
Web Protocols
MalwareCuckoo Stealer

Cuckoo Stealer can use the curl API for C2 communications.

T1074.001
Local Data Staging
MalwareCuckoo Stealer

Cuckoo Stealer has staged collected application data from Safari, Notes, and Keychain to `/var/folder`.

T1082
System Information Discovery
MalwareCuckoo Stealer

Cuckoo Stealer can gather information about the OS version and hardware on compromised hosts.

T1083
File and Directory Discovery
MalwareCuckoo Stealer

Cuckoo Stealer can search for files associated with specific applications.

T1095
Non-Application Layer Protocol
MalwareCuckoo Stealer

Cuckoo Stealer can use sockets for communications to its C2 server.

T1113
Screen Capture
MalwareCuckoo Stealer

Cuckoo Stealer can run `screencapture` to collect screenshots from compromised hosts.

T1140
Deobfuscate/Decode Files or Information
MalwareCuckoo Stealer

Cuckoo Stealer strings are deobfuscated prior to execution.

T1217
Browser Information Discovery
MalwareCuckoo Stealer

Cuckoo Stealer can collect bookmarks, cookies, and history from Safari.

T1518
Software Discovery
MalwareCuckoo Stealer

Cuckoo Stealer has the ability to search systems for installed applications.

T1543.001
Launch Agent
MalwareCuckoo Stealer

Cuckoo Stealer can achieve persistence by creating launch agents to repeatedly execute malicious payloads.

T1553.001
Gatekeeper Bypass
MalwareCuckoo Stealer

Cuckoo Stealer can use `xattr -d com.apple.quarantine` to remove the quarantine flag attribute.

T1555.001
Keychain
MalwareCuckoo Stealer

Cuckoo Stealer can capture files from a targeted user's keychain directory.

T1564.001
Hidden Files and Directories
MalwareCuckoo Stealer

Cuckoo Stealer has copied its binary and the victim's scraped password into a hidden folder in the `/Users` directory.

T1569.001
Launchctl
MalwareCuckoo Stealer

Cuckoo Stealer can use `launchctl` to load a LaunchAgent for persistence.

T1614
System Location Discovery
MalwareCuckoo Stealer

Cuckoo Stealer can determine the geographical location of a victim host by checking the language.

T1614.001
System Language Discovery
MalwareCuckoo Stealer

Cuckoo Stealer can check the systems `LANG` environmental variable to prevent infecting devices from Armenia (`hy_AM`), Belarus (`be_BY`), Kazakhstan (`kk_KZ`), Russia (`ru_RU`), and Ukraine (`uk_UA`).

T1647
Plist File Modification
MalwareCuckoo Stealer

Cuckoo Stealer can create and populate property list (plist) files to enable execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.