Stokes, P. (2024, May 9). macOS Cuckoo Stealer | Ensuring Detection and Defense as New Samples Rapidly Emerge. Retrieved August 20, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.008 Stripped Payloads |
MalwareCuckoo Stealer | Cuckoo Stealer is a stripped binary payload. |
| T1027.013 Encrypted/Encoded File |
MalwareCuckoo Stealer | Cuckoo Stealer strings are XOR-encrypted. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareCuckoo Stealer | Cuckoo Stealer has copied and renamed itself to DumpMediaSpotifyMusicConverter. |
| T1059.002 AppleScript |
MalwareCuckoo Stealer | Cuckoo Stealer can use osascript to generate a password-stealing prompt, duplicate files and folders, and set environmental variables. |
| T1082 System Information Discovery |
MalwareCuckoo Stealer | Cuckoo Stealer can gather information about the OS version and hardware on compromised hosts. |
| T1083 File and Directory Discovery |
MalwareCuckoo Stealer | Cuckoo Stealer can search for files associated with specific applications. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCuckoo Stealer | Cuckoo Stealer strings are deobfuscated prior to execution. |
| T1543.001 Launch Agent |
MalwareCuckoo Stealer | Cuckoo Stealer can achieve persistence by creating launch agents to repeatedly execute malicious payloads. |
| T1553.001 Gatekeeper Bypass |
MalwareCuckoo Stealer | Cuckoo Stealer can use `xattr -d com.apple.quarantine` to remove the quarantine flag attribute. |
| T1564.001 Hidden Files and Directories |
MalwareCuckoo Stealer | Cuckoo Stealer has copied its binary and the victim's scraped password into a hidden folder in the `/Users` directory. |
| T1647 Plist File Modification |
MalwareCuckoo Stealer | Cuckoo Stealer can create and populate property list (plist) files to enable execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.