S1048macOS

S1048macOS.OSAMiner

Platforms
1
ATT&CK
14.1
References
3

Description

[macOS.OSAMiner](https://attack.mitre.org/software/S1048) is a Monero mining trojan that was first observed in 2018; security researchers assessed [macOS.OSAMiner](https://attack.mitre.org/software/S1048) may have been circulating since at least 2015. [macOS.OSAMiner](https://attack.mitre.org/software/S1048) is known for embedding one run-only AppleScript into another, which helped the malware evade full analysis for five years due to a lack of Apple event (AEVT) analysis tools.(Citation: SentinelLabs reversing run-only applescripts 2021)(Citation: VMRay OSAMiner dynamic analysis 2021)

Platforms· 1

macOS

References

  1. https://attack.mitre.org/software/S1048
  2. https://www.sentinelone.com/labs/fade-dead-adventures-in-reversing-malicious-run-only-applescripts/
  3. https://www.vmray.com/cyber-security-blog/osaminer-uses-applescripts-evade-detection-malware-analysis-spotlight/

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
CookieMiner
Software
MacMa
Software
OSX/Shlayer
Software
CoinMiner
Software
CpuMeaner
Software
LoudMiner
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, SQUR.