CookieMiner

MITRE ATT&CK: S0492 View on attack.mitre.org

Aliases: CookieMiner

First seen
2019-01-01 00:00:00
Malware type
cryptominer, credential-stealer
Family
Malware family
Operating systems
macos
Profile updated
2026-07-07 15:31:03

Targeted industries: financial-services

Context

CookieMiner is mac-based malware that targets information associated with cryptocurrency exchanges as well as enabling cryptocurrency mining on the victim system itself. It was first discovered in the wild in 2019.

Detection coverage

  • 178 Sigma rules

Malware & tools used

  • Credentials from Web Browsers (attack-pattern)
  • Exfiltration Over Unencrypted Non-C2 Protocol (attack-pattern)
  • Compute Hijacking (attack-pattern)
  • Steal Web Session Cookie (attack-pattern)
  • Disable or Modify System Firewall (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Data from Local System (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Command Obfuscation (attack-pattern)
  • Unix Shell (attack-pattern)
  • Launch Agent (attack-pattern)
  • Python (attack-pattern)

Reports & references

  • MITRE ATT&CK — S0492 (report)
  • Palo Alto Unit 42 — Mac Malware Steals Cryptocurrency Exchanges Cookies (report)

External references