CookieMiner is a macOS-focused information-stealing malware associated with theft of browser-stored data and cryptocurrency-related targeting. It is known for stealing Google Chrome credentials, including saved usernames, passwords, and payment card data, as well as browser cookies from Google Chrome and Apple Safari. By harvesting cookies in addition to credentials, it can facilitate abuse of authenticated web sessions. CookieMiner has also been observed collecting iPhone text messages from local iTunes backup data, indicating broader theft of user information beyond browser artifacts.
The malware includes multiple defense-evasion and anti-analysis behaviors. It checks for the presence of Little Snitch, a macOS network monitoring and firewall product, and terminates execution if it detects that software. It also uses Base64 encoding to obfuscate scripts and performs browser decryption and extraction operations to access protected Chrome data.
For persistence, CookieMiner installs multiple Launch Agents on macOS, including to support continued operation of cryptocurrency-mining components. It has also been observed exfiltrating stolen data over HTTP using command-line upload functionality. Overall, CookieMiner is best characterized as a macOS infostealer with credential theft, cookie theft, persistence, defense evasion, and data exfiltration capabilities, with notable overlap between information theft and cryptocurrency-motivated activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
"Action RAT's commands, strings, and domains can be Base64 encoded within the payload." / "ADVSTORESHELL... strings... encrypted with an XOR-based algorithm; some strings are also encrypted with 3DES and reversed." / "APT29 has used encoded PowerShell commands." / "APT41 used VMProtected binaries..."
Grandoreiro can steal cookie data and credentials from Google Chrome... Kimsuky has used browser extensions including Google Chrome to steal passwords and cookies from browsers... Inception used a browser plugin to steal passwords and sessions
Agent Tesla can gather credentials from a number of browsers... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge... SELECT action_url, username_value, password_value FROM logins; CryptUnprotectData
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Stealer malware that retrieves data such as iPhone text messages from backup files.
Credential-stealing malware that targets Chrome-saved usernames, passwords, and credit card data.
Malware that leverages Chrome decryption and extraction operations.
Malware that leverages Chrome decryption and extraction operations, likely for credential or cookie theft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.