Objective-See recaps 2019 Mac malware year
Objective-See's annual roundup details 2019 macOS malware including CookieMiner, Lazarus's Yort implant, Siggen backdoor, and BirdMiner cryptominer.
This Objective-See year-in-review consolidates analysis of new macOS malware families observed throughout 2019, providing infection vectors, persistence mechanisms, and capabilities for each. Highlights include OSX.CookieMiner, an evolution of DarthMiner that mines Koto cryptocurrency while stealing Safari/Chrome cookies, saved passwords, credit card data, and iPhone SMS backups to bypass 2FA on cryptocurrency exchange accounts; OSX.Yort, a lightweight Lazarus Group first-stage implant delivered via malicious Office macro documents targeting cryptocurrency professionals, supporting file upload/download and arbitrary command execution over libcurl-based C2; OSX.Siggen, distributed as a trojanized WhatsApp application via a phishing/drive-by site, which persists via launch agent and ultimately deploys a Python-based backdoor leveraging the public Evil.OSX post-exploitation kit; and OSX.BirdMiner (LoudMiner), a Linux cryptominer bundled in nearly 100 pirated VST/audio production applications (e.g., cracked Ableton Live) that runs under QEMU emulation and persists via LaunchDaemons.
Across these samples, common themes emerge: reliance on social engineering (pirated software, fake WhatsApp installer, malicious macro documents) rather than exploited vulnerabilities, use of LaunchAgents/LaunchDaemons for persistence, and a mix of financially motivated cryptomining/credential-theft tooling alongside targeted nation-state espionage activity (Yort/Lazarus). The report serves as a reference archive with downloadable samples and IOCs for defenders and researchers rather than a single incident advisory, and reflects the routine diversity of commodity and targeted Mac threats seen in 2019.
Mentioned in this report
Source reporting: https://objective-see.org/blog/blog_0x53.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free