Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Cuckoo Stealer

Cuckoo Stealer

TLP:CLEAR
Family

AI Analysis

· 4 hours ago

Executive Summary

Cuckoo Stealer is a macOS spyware/infostealer that distributes via trojanized PUPs, harvesting browser credentials and system information before exfiltrating data to a remote C2 over HTTPS. The universal binary can run on both Intel and Apple Silicon Macs, allowing widespread infection across the platform. It achieves persistence through launch agents/daemons and hides in legitimate‑looking installers.

Enhanced Description

Cuckoo Stealer is a macOS‑native threat that functions as both spyware and an infostealer. Delivered in the form of a universal Mach-O binary, it is designed to run on Intel‑based Macs as well as Apple Silicon systems. The malware has been observed since at least early 2024 and spreads through trojanized versions of potentially unwanted programs (PUPs) such as converters, cleaners, installers, and uninstallers that users often download from the internet or corporate software repositories. Once executed, Cuckoo Stealer hooks into web browsers to harvest stored credentials, cookies, and autofill data, then collects system information including OS version, hardware identifiers, installed applications, and network configuration. The stolen data is exfiltrated over encrypted HTTPS connections to a remote command‑and‑control (C2) server that is frequently updated via dynamic DNS mechanisms, making the exfiltration path hard to block through static IP filtering. Persistence is achieved by creating launch agents or daemons in user and system directories, ensuring that the malware survives reboot cycles without requiring administrative privileges. The threat model focuses on credential theft for lateral movement within corporate networks or personal accounts. Because it can run natively on both Intel and ARM architectures, attackers can target a broad range of Mac users without needing to compile separate binaries. By embedding itself in commonly downloaded utilities, Cuckoo Stealer exploits user trust and bypasses traditional antivirus heuristics that focus only on unsigned executables. While specific post‑infection behavior such as screenshot capture or plugin injection has not yet been fully documented by public repositories, the malware’s design aligns with other macOS infostealers that perform similar data collection and exfiltration workflows. Defensive strategies must therefore incorporate both behavioral detection of credential-harvesting activity and traditional signature-based blocking of known PUP bundles.

Key Capabilities

  • Harvests stored browser credentials (username/passwords, cookies)
  • Collects system and network information (OS version, installed apps, IP addresses)
  • Exfiltrates stolen data to remote HTTPS C2 servers using dynamic DNS
  • Persists via LaunchAgents and Daemon entries in user and system directories
  • Distributes through trojanized PUP installers such as converters, cleaners and uninstallers

Recommended Actions

  • Block download and execution of known PUPs from unverified sources

Description

Cuckoo Stealer is a macOS malware with characteristics of spyware and an infostealer that has been in use since at least 2024. Cuckoo Stealer is a universal Mach-O binary that can run on Intel or ARM-based Macs and has been spread through trojanized versions of various potentially unwanted programs or PUP's such as converters, cleaners, and uninstallers.(Citation: Kandji Cuckoo April 2024)(Citation: SentinelOne Cuckoo Stealer May 2024)

Details

Type
Malware
Platforms
Macos
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.