CookieMiner

CookieMiner is mac-based malware that targets information associated with cryptocurrency exchanges as well as enabling cryptocurrency mining on the victim system itself. It was first discovered in the wild in 2019.[1]

ID: S0492
Type: MALWARE
Platforms: macOS
Version: 1.1
Created: 22 July 2020
Last Modified: 22 March 2023

Techniques Used

Domain ID Name Use
Enterprise T1555 .003 从密码存储中获取凭证: Credentials from Web Browsers

CookieMiner can steal saved usernames and passwords in Chrome as well as credit card credentials.[1]

Enterprise T1005 从本地系统获取数据

CookieMiner has retrieved iPhone text messages from iTunes phone backup files.[1]

Enterprise T1543 .001 创建或修改系统进程: Launch Agent

CookieMiner has installed multiple new Launch Agents in order to maintain persistence for cryptocurrency mining software.[1]

Enterprise T1140 反混淆/解码文件或信息

CookieMiner has used Google Chrome's decryption and extraction operations.[1]

Enterprise T1059 .004 命令与脚本解释器: Unix Shell

CookieMiner has used a Unix shell script to run a series of commands targeting macOS.[1]

.006 命令与脚本解释器: Python

CookieMiner has used python scripts on the user’s system, as well as the Python variant of the Empire agent, EmPyre.[1]

Enterprise T1562 .004 妨碍防御: Disable or Modify System Firewall

CookieMiner has checked for the presence of "Little Snitch", macOS network monitoring and application firewall software, stopping and exiting if it is found.[1]

Enterprise T1083 文件和目录发现

CookieMiner has looked for files in the user's home directory with "wallet" in their name using find.[1]

Enterprise T1048 .003 替代协议渗出: Exfiltration Over Unencrypted Non-C2 Protocol

CookieMiner has used the curl --upload-file command to exfiltrate data over HTTP.[1]

Enterprise T1027 .010 混淆文件或信息: Command Obfuscation

CookieMiner has used base64 encoding to obfuscate scripts on the system.[1]

Enterprise T1539 窃取Web会话Cookie

CookieMiner can steal Google Chrome and Apple Safari browser cookies from the victim’s machine. [1]

Enterprise T1496 .001 资源劫持: Compute Hijacking

CookieMiner has loaded coinmining software onto systems to mine for Koto cryptocurrency. [1]

Enterprise T1518 .001 软件发现: Security Software Discovery

CookieMiner has checked for the presence of "Little Snitch", macOS network monitoring and application firewall software, stopping and exiting if it is found.[1]

Enterprise T1105 输入工具传输

CookieMiner can download additional scripts from a web server.[1]

References