macOS.OSAMiner

MITRE ATT&CK: S1048 View on attack.mitre.org

Aliases: macOS.OSAMiner

First seen
2015-01-01 00:00:00
Malware type
cryptominer, trojan
Family
Malware family
Operating systems
macos
Profile updated
2026-07-07 15:28:44

Context

macOS.OSAMiner is a Monero mining trojan that was first observed in 2018; security researchers assessed macOS.OSAMiner may have been circulating since at least 2015. macOS.OSAMiner is known for embedding one run-only AppleScript into another, which helped the malware evade full analysis for five years due to a lack of Apple event (AEVT) analysis tools.

Detection coverage

  • 276 Sigma rules

Malware & tools used

  • Disable or Modify Tools (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Local Storage Discovery (attack-pattern)
  • System Checks (attack-pattern)
  • Stripped Payloads (attack-pattern)
  • Embedded Payloads (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Launch Agent (attack-pattern)
  • Launchctl (attack-pattern)
  • Process Discovery (attack-pattern)
  • AppleScript (attack-pattern)

Reports & references

  • MITRE ATT&CK — S1048 (report)
  • sentinelone.com — Fade Dead Adventures In Reversing Malicious Run Only Applescripts (report)
  • vmray.com — Osaminer Uses Applescripts Evade Detection Malware Analysis Spotlight (report)

External references