Executive Summary
Cuckoo Stealer is a macOS spyware/infostealer that distributes via trojanized PUPs, harvesting browser credentials and system information before exfiltrating data to a remote C2 over HTTPS. The universal binary can run on both Intel and Apple Silicon Macs, allowing widespread infection across the platform. It achieves persistence through launch agents/daemons and hides in legitimate‑looking installers.
Enhanced Description
Cuckoo Stealer is a macOS‑native threat that functions as both spyware and an infostealer. Delivered in the form of a universal Mach-O binary, it is designed to run on Intel‑based Macs as well as Apple Silicon systems. The malware has been observed since at least early 2024 and spreads through trojanized versions of potentially unwanted programs (PUPs) such as converters, cleaners, installers, and uninstallers that users often download from the internet or corporate software repositories. Once executed, Cuckoo Stealer hooks into web browsers to harvest stored credentials, cookies, and autofill data, then collects system information including OS version, hardware identifiers, installed applications, and network configuration. The stolen data is exfiltrated over encrypted HTTPS connections to a remote command‑and‑control (C2) server that is frequently updated via dynamic DNS mechanisms, making the exfiltration path hard to block through static IP filtering. Persistence is achieved by creating launch agents or daemons in user and system directories, ensuring that the malware survives reboot cycles without requiring administrative privileges. The threat model focuses on credential theft for lateral movement within corporate networks or personal accounts. Because it can run natively on both Intel and ARM architectures, attackers can target a broad range of Mac users without needing to compile separate binaries. By embedding itself in commonly downloaded utilities, Cuckoo Stealer exploits user trust and bypasses traditional antivirus heuristics that focus only on unsigned executables. While specific post‑infection behavior such as screenshot capture or plugin injection has not yet been fully documented by public repositories, the malware’s design aligns with other macOS infostealers that perform similar data collection and exfiltration workflows. Defensive strategies must therefore incorporate both behavioral detection of credential-harvesting activity and traditional signature-based blocking of known PUP bundles.
Key Capabilities
Recommended Actions
Cuckoo Stealer is a macOS malware with characteristics of spyware and an infostealer that has been in use since at least 2024. Cuckoo Stealer is a universal Mach-O binary that can run on Intel or ARM-based Macs and has been spread through trojanized versions of various potentially unwanted programs or PUP's such as converters, cleaners, and uninstallers.(Citation: Kandji Cuckoo April 2024)(Citation: SentinelOne Cuckoo Stealer May 2024)