New 'Cuckoo' Persistent macOS Spyware Targeting Intel and Arm Macs
ID: 0af67859-3705-5522-ac4e-042099f5ecb2
STIX ID: report--0af67859-3705-5522-ac4e-042099f5ecb2
Feed Name: The Hacker News
Threat Score
Cybersecurity researchers discovered 'Cuckoo', a universal Mach-O macOS information stealer distributed via trojanized apps on multiple software download sites; it performs geofencing, harvests keychain, browser, crypto wallet and app data, uses osascript to phish admin passwords, and achieves persistence via LaunchAgent, with analysts observing a spike in samples and delivery through cracked or bundled applications.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
