CookieMiner is mac-based malware that targets information associated with cryptocurrency exchanges as well as enabling cryptocurrency mining on the victim system itself. It was first discovered in the wild in 2019.[1]
| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1555 | .003 | 从密码存储中获取凭证: Credentials from Web Browsers |
CookieMiner can steal saved usernames and passwords in Chrome as well as credit card credentials.[1] |
| Enterprise | T1005 | 从本地系统获取数据 |
CookieMiner has retrieved iPhone text messages from iTunes phone backup files.[1] |
|
| Enterprise | T1543 | .001 | 创建或修改系统进程: Launch Agent |
CookieMiner has installed multiple new Launch Agents in order to maintain persistence for cryptocurrency mining software.[1] |
| Enterprise | T1140 | 反混淆/解码文件或信息 |
CookieMiner has used Google Chrome's decryption and extraction operations.[1] |
|
| Enterprise | T1059 | .004 | 命令与脚本解释器: Unix Shell |
CookieMiner has used a Unix shell script to run a series of commands targeting macOS.[1] |
| .006 | 命令与脚本解释器: Python |
CookieMiner has used python scripts on the user’s system, as well as the Python variant of the Empire agent, EmPyre.[1] |
||
| Enterprise | T1562 | .004 | 妨碍防御: Disable or Modify System Firewall |
CookieMiner has checked for the presence of "Little Snitch", macOS network monitoring and application firewall software, stopping and exiting if it is found.[1] |
| Enterprise | T1083 | 文件和目录发现 |
CookieMiner has looked for files in the user's home directory with "wallet" in their name using |
|
| Enterprise | T1048 | .003 | 替代协议渗出: Exfiltration Over Unencrypted Non-C2 Protocol |
CookieMiner has used the |
| Enterprise | T1027 | .010 | 混淆文件或信息: Command Obfuscation |
CookieMiner has used base64 encoding to obfuscate scripts on the system.[1] |
| Enterprise | T1539 | 窃取Web会话Cookie |
CookieMiner can steal Google Chrome and Apple Safari browser cookies from the victim’s machine. [1] |
|
| Enterprise | T1496 | .001 | 资源劫持: Compute Hijacking |
CookieMiner has loaded coinmining software onto systems to mine for Koto cryptocurrency. [1] |
| Enterprise | T1518 | .001 | 软件发现: Security Software Discovery |
CookieMiner has checked for the presence of "Little Snitch", macOS network monitoring and application firewall software, stopping and exiting if it is found.[1] |
| Enterprise | T1105 | 输入工具传输 |
CookieMiner can download additional scripts from a web server.[1] |
|