Kohler, A. and Lopez, C. (2024, April 30). Malware: Cuckoo Behaves Like Cross Between Infostealer and Spyware. Retrieved August 20, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.008 Stripped Payloads |
MalwareCuckoo Stealer | Cuckoo Stealer is a stripped binary payload. |
| T1027.013 Encrypted/Encoded File |
MalwareCuckoo Stealer | Cuckoo Stealer strings are XOR-encrypted. |
| T1033 System Owner/User Discovery |
MalwareCuckoo Stealer | Cuckoo Stealer can discover and send the username from a compromised host to C2. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareCuckoo Stealer | Cuckoo Stealer has copied and renamed itself to DumpMediaSpotifyMusicConverter. |
| T1041 Exfiltration Over C2 Channel |
MalwareCuckoo Stealer | Cuckoo Stealer can send information about the targeted system to C2 including captured passwords, OS build, hostname, and username. |
| T1056.002 GUI Input Capture |
MalwareCuckoo Stealer | Cuckoo Stealer has captured passwords by prompting victims with a “macOS needs to access System Settings” GUI window. |
| T1057 Process Discovery |
MalwareCuckoo Stealer | Cuckoo Stealer can use `ps aux` to enumerate running processes. |
| T1059.002 AppleScript |
MalwareCuckoo Stealer | Cuckoo Stealer can use osascript to generate a password-stealing prompt, duplicate files and folders, and set environmental variables. |
| T1059.004 Unix Shell |
MalwareCuckoo Stealer | Cuckoo Stealer can spawn a bash shell to enable execution on compromised hosts. |
| T1071.001 Web Protocols |
MalwareCuckoo Stealer | Cuckoo Stealer can use the curl API for C2 communications. |
| T1074.001 Local Data Staging |
MalwareCuckoo Stealer | Cuckoo Stealer has staged collected application data from Safari, Notes, and Keychain to `/var/folder`. |
| T1082 System Information Discovery |
MalwareCuckoo Stealer | Cuckoo Stealer can gather information about the OS version and hardware on compromised hosts. |
| T1083 File and Directory Discovery |
MalwareCuckoo Stealer | Cuckoo Stealer can search for files associated with specific applications. |
| T1095 Non-Application Layer Protocol |
MalwareCuckoo Stealer | Cuckoo Stealer can use sockets for communications to its C2 server. |
| T1113 Screen Capture |
MalwareCuckoo Stealer | Cuckoo Stealer can run `screencapture` to collect screenshots from compromised hosts. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCuckoo Stealer | Cuckoo Stealer strings are deobfuscated prior to execution. |
| T1217 Browser Information Discovery |
MalwareCuckoo Stealer | Cuckoo Stealer can collect bookmarks, cookies, and history from Safari. |
| T1518 Software Discovery |
MalwareCuckoo Stealer | Cuckoo Stealer has the ability to search systems for installed applications. |
| T1543.001 Launch Agent |
MalwareCuckoo Stealer | Cuckoo Stealer can achieve persistence by creating launch agents to repeatedly execute malicious payloads. |
| T1553.001 Gatekeeper Bypass |
MalwareCuckoo Stealer | Cuckoo Stealer can use `xattr -d com.apple.quarantine` to remove the quarantine flag attribute. |
| T1555.001 Keychain |
MalwareCuckoo Stealer | Cuckoo Stealer can capture files from a targeted user's keychain directory. |
| T1564.001 Hidden Files and Directories |
MalwareCuckoo Stealer | Cuckoo Stealer has copied its binary and the victim's scraped password into a hidden folder in the `/Users` directory. |
| T1569.001 Launchctl |
MalwareCuckoo Stealer | Cuckoo Stealer can use `launchctl` to load a LaunchAgent for persistence. |
| T1614 System Location Discovery |
MalwareCuckoo Stealer | Cuckoo Stealer can determine the geographical location of a victim host by checking the language. |
| T1614.001 System Language Discovery |
MalwareCuckoo Stealer | Cuckoo Stealer can check the systems `LANG` environmental variable to prevent infecting devices from Armenia (`hy_AM`), Belarus (`be_BY`), Kazakhstan (`kk_KZ`), Russia (`ru_RU`), and Ukraine (`uk_UA`). |
| T1647 Plist File Modification |
MalwareCuckoo Stealer | Cuckoo Stealer can create and populate property list (plist) files to enable execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.