Cuckoo Stealer
MITRE ATT&CK: S1153 View on attack.mitre.org
Aliases: Cuckoo Stealer
- First seen
- 2024-01-01 00:00:00
- Malware type
- spyware, credential-stealer, trojan
- Family
- Malware family
- Operating systems
- macos
- Profile updated
- 2026-07-07 15:28:25
Targeted industries: technology-and-telecommunications media-and-entertainment professional-services
Context
Cuckoo Stealer is a macOS malware with characteristics of spyware and an infostealer that has been in use since at least 2024. Cuckoo Stealer is a universal Mach-O binary that can run on Intel or ARM-based Macs and has been spread through trojanized versions of various potentially unwanted programs or PUP's such as converters, cleaners, and uninstallers.
Detection coverage
- 212 Sigma rules
Malware & tools used
- Encrypted/Encoded File (attack-pattern)
- Hidden Files and Directories (attack-pattern)
- System Language Discovery (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- System Location Discovery (attack-pattern)
- Launchctl (attack-pattern)
- Software Discovery (attack-pattern)
- Plist File Modification (attack-pattern)
- Screen Capture (attack-pattern)
- Local Data Staging (attack-pattern)
- Process Discovery (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Stripped Payloads (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Web Protocols (attack-pattern)
- Unix Shell (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- Gatekeeper Bypass (attack-pattern)
- Launch Agent (attack-pattern)
- AppleScript (attack-pattern)
- Keychain (attack-pattern)
- System Information Discovery (attack-pattern)
- GUI Input Capture (attack-pattern)
Reports & references
- MITRE ATT&CK — S1153 (report)
- kandji.io — Malware Cuckoo Infostealer Spyware (report)
- sentinelone.com — Macos Cuckoo Stealer Ensuring Detection And Defense As New Samples Rapidly Emerge (report)