macOS.OSAMiner
MITRE ATT&CK: S1048 View on attack.mitre.org
Aliases: macOS.OSAMiner
- First seen
- 2015-01-01 00:00:00
- Malware type
- cryptominer, trojan
- Family
- Malware family
- Operating systems
- macos
- Profile updated
- 2026-07-07 15:28:44
Context
macOS.OSAMiner is a Monero mining trojan that was first observed in 2018; security researchers assessed macOS.OSAMiner may have been circulating since at least 2015. macOS.OSAMiner is known for embedding one run-only AppleScript into another, which helped the malware evade full analysis for five years due to a lack of Apple event (AEVT) analysis tools.
Detection coverage
- 276 Sigma rules
Malware & tools used
- Disable or Modify Tools (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Local Storage Discovery (attack-pattern)
- System Checks (attack-pattern)
- Stripped Payloads (attack-pattern)
- Embedded Payloads (attack-pattern)
- System Information Discovery (attack-pattern)
- Launch Agent (attack-pattern)
- Launchctl (attack-pattern)
- Process Discovery (attack-pattern)
- AppleScript (attack-pattern)
Reports & references
- MITRE ATT&CK — S1048 (report)
- sentinelone.com — Fade Dead Adventures In Reversing Malicious Run Only Applescripts (report)
- vmray.com — Osaminer Uses Applescripts Evade Detection Malware Analysis Spotlight (report)