logo

New 'Cuckoo' Persistent macOS Spyware Targeting Intel and Arm Macs

ID: 0af67859-3705-5522-ac4e-042099f5ecb2

STIX ID: report--0af67859-3705-5522-ac4e-042099f5ecb2

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-05-06

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Cybersecurity researchers discovered 'Cuckoo', a universal Mach-O macOS information stealer distributed via trojanized apps on multiple software download sites; it performs geofencing, harvests keychain, browser, crypto wallet and app data, uses osascript to phish admin passwords, and achieves persistence via LaunchAgent, with analysts observing a spike in samples and delivery through cracked or bundled applications.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.