ATT&CKSoftwareCuckoo Stealer

Cuckoo Stealer

S1153

Malware.View on attack.mitre.org

About this malware

Cuckoo Stealer is a macOS malware with characteristics of spyware and an infostealer that has been in use since at least 2024. Cuckoo Stealer is a universal Mach-O binary that can run on Intel or ARM-based Macs and has been spread through trojanized versions of various potentially unwanted programs or PUP's such as converters, cleaners, and uninstallers.

Techniques used26

Procedure examples26

TechniqueProcedure example
T1027.008
Stripped Payloads

Cuckoo Stealer is a stripped binary payload.

T1027.013
Encrypted/Encoded File

Cuckoo Stealer strings are XOR-encrypted.

T1033
System Owner/User Discovery

Cuckoo Stealer can discover and send the username from a compromised host to C2.

T1036.005
Match Legitimate Resource Name or Location

Cuckoo Stealer has copied and renamed itself to DumpMediaSpotifyMusicConverter.

T1041
Exfiltration Over C2 Channel

Cuckoo Stealer can send information about the targeted system to C2 including captured passwords, OS build, hostname, and username.

T1056.002
GUI Input Capture

Cuckoo Stealer has captured passwords by prompting victims with a “macOS needs to access System Settings” GUI window.

T1057
Process Discovery

Cuckoo Stealer can use `ps aux` to enumerate running processes.

T1059.002
AppleScript

Cuckoo Stealer can use osascript to generate a password-stealing prompt, duplicate files and folders, and set environmental variables.

T1059.004
Unix Shell

Cuckoo Stealer can spawn a bash shell to enable execution on compromised hosts.

T1071.001
Web Protocols

Cuckoo Stealer can use the curl API for C2 communications.

T1074.001
Local Data Staging

Cuckoo Stealer has staged collected application data from Safari, Notes, and Keychain to `/var/folder`.

T1082
System Information Discovery

Cuckoo Stealer can gather information about the OS version and hardware on compromised hosts.

T1083
File and Directory Discovery

Cuckoo Stealer can search for files associated with specific applications.

T1095
Non-Application Layer Protocol

Cuckoo Stealer can use sockets for communications to its C2 server.

T1113
Screen Capture

Cuckoo Stealer can run `screencapture` to collect screenshots from compromised hosts.

View all 26 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. Kandji Cuckoo April 2024 Open source
    Kohler, A. and Lopez, C. (2024, April 30). Malware: Cuckoo Behaves Like Cross Between Infostealer and Spyware. Retrieved August 20, 2024.
  2. SentinelOne Cuckoo Stealer May 2024 Open source
    Stokes, P. (2024, May 9). macOS Cuckoo Stealer | Ensuring Detection and Defense as New Samples Rapidly Emerge. Retrieved August 20, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.