Cuckoo Stealer is a macOS-focused information stealer with remote-access functionality that has been distributed through social-engineering campaigns, particularly fake Homebrew installation pages and broader ClickFix-style lures. The malware relies on user-assisted execution through native macOS tools, allowing operators to bypass Gatekeeper protections without exploiting a software vulnerability. Campaigns have used counterfeit software-installation workflows and deceptive prompts to convince victims to run malicious shell commands, after which a second-stage payload is retrieved and executed.
Once active, Cuckoo Stealer collects a broad range of host and user data. Confirmed behaviors include theft of Safari bookmarks, cookies, and browsing history; collection of system information such as hostname, OS build, and username; discovery of installed applications; and staging of data from Safari, Notes, and Keychain prior to exfiltration. It has also been observed harvesting passwords through native-looking macOS credential prompts and transmitting stolen information to command-and-control infrastructure. The malware can determine victim geography through language settings and implements locale-based filtering to avoid infecting systems configured for several CIS-related locales.
Cuckoo Stealer uses defense-evasion and persistence mechanisms typical of modern macOS malware. It has copied itself and stolen data into hidden directories, renamed itself to resemble legitimate software, removed quarantine attributes, and established persistence through LaunchAgents that repeatedly execute the payload. Communications with command-and-control infrastructure have been observed over socket-based channels and encrypted HTTPS in reported campaigns. Documented remote capabilities include command execution, controlled exfiltration, rebooting, and self-removal, supporting characterization as both an infostealer and a lightweight RAT.
The malware has been associated with fake Homebrew malvertising and ClickFix-style campaigns active across 2024 through 2026, alongside other macOS stealers such as Atomic Stealer and SHub Stealer. Developer and enterprise macOS systems are especially attractive targets because the lures imitate common administrative and software-installation workflows, increasing the likelihood of successful credential theft, persistence, and theft of sensitive local application data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A macOS infostealer used in ClickFix campaigns to exfiltrate sensitive user data from compromised systems.
Information stealer delivered via fake Homebrew pages that mimic the official install flow to trick users into installing malicious commands, enabling secret exfiltration and possible persistent access.
macOS infostealer/RAT delivered via typosquatted Homebrew-themed ClickFix lures; establishes LaunchAgent persistence, removes quarantine attributes, uses encrypted HTTPS C2, and steals browser credentials/session tokens, Keychain data, notes/messaging sessions, VPN/FTP configs, and data from numerous crypto wallet apps.
Second-stage macOS infostealer/RAT delivered via a ClickFix/Homebrew-typosquat paste-and-run command. Establishes LaunchAgent persistence, removes quarantine attributes, uses encrypted HTTPS C2 (X25519 ECDH-derived), supports remote command execution and file exfiltration, and steals high-value data including browser credentials/cookies, Keychain, Apple Notes, Discord/Telegram sessions, VPN/FTP configs, Steam sessions, and data from 20+ cryptocurrency wallets.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.