S1153: Cuckoo Stealer
Cuckoo Stealer is a macOS malware with characteristics of spyware and an infostealer that has been in use since at least 2024. Cuckoo Stealer is a universal Mach-O binary that can run on Intel or ARM-based Macs and has been spread through trojanized versions of various potentially unwanted programs or PUP's such as converters, cleaners, and uninstallers.[1][2]
Security context for executives and security teams
S1153: Cuckoo Stealer describes [Cuckoo Stealer](https://attack.mitre.org/software/S1153) is a macOS malware with characteristics of spyware and an infostealer that has been in use since at least 2024. [Cuckoo Stealer](https://attack.mitre.org/software/S1153) is a universal Mach-O binary that can run on Intel or ARM-based Macs and has been spread through trojanized versions of various potentially unwanted programs or PUP's such as converters, cleaners, and uninstallers.(Citation: Kandji Cuckoo April 2024)(Citation: SentinelOne Cuckoo Stealer May ...
Executive priority
S1153: Cuckoo Stealer is an official MITRE ATT&CK software. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate S1153: Cuckoo Stealer by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (macOS), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
- Network, endpoint, and security-tool telemetry
Detection direction
- Validate whether S1153: Cuckoo Stealer appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Cuckoo Stealer
Cuckoo Stealer is a macOS malware with characteristics of spyware and an infostealer that has been in use since at least 2024. Cuckoo Stealer is a universal Mach-O binary that can run on Intel or ARM-based Macs and has been spread through trojanized versions of various potentially unwanted programs or PUP's such as converters, cleaners, and uninstallers.[1][2]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1027.013 | Encrypted/Encoded FileSub-technique | Cuckoo Stealer strings are XOR-encrypted.[1][2] |
| Enterprise | T1564.001 | Hidden Files and DirectoriesSub-technique | Cuckoo Stealer has copied its binary and the victim's scraped password into a hidden folder in the `/Users` directory.[1][2] |
| Enterprise | T1614.001 | System Language DiscoverySub-technique | Cuckoo Stealer can check the systems `LANG` environmental variable to prevent infecting devices from Armenia (`hy_AM`), Belarus (`be_BY`), Kazakhstan (`kk_KZ`), Russia (`ru_RU`), and Ukraine (`uk_UA`).[1] |
| Enterprise | T1033 | System Owner/User Discovery | Cuckoo Stealer can discover and send the username from a compromised host to C2.[1] |
| Enterprise | T1614 | System Location Discovery | Cuckoo Stealer can determine the geographical location of a victim host by checking the language.[1] |
| Enterprise | T1569.001 | LaunchctlSub-technique | Cuckoo Stealer can use `launchctl` to load a LaunchAgent for persistence.[1] |
| Enterprise | T1518 | Software Discovery | Cuckoo Stealer has the ability to search systems for installed applications.[1] |
| Enterprise | T1647 | Plist File Modification | Cuckoo Stealer can create and populate property list (plist) files to enable execution.[1][2] |
| Enterprise | T1113 | Screen Capture | Cuckoo Stealer can run `screencapture` to collect screenshots from compromised hosts. [1] |
| Enterprise | T1074.001 | Local Data StagingSub-technique | Cuckoo Stealer has staged collected application data from Safari, Notes, and Keychain to `/var/folder`.[1] |
| Enterprise | T1057 | Process Discovery | Cuckoo Stealer can use `ps aux` to enumerate running processes.[1] |
| Enterprise | T1083 | File and Directory Discovery | Cuckoo Stealer can search for files associated with specific applications.[1][2] |
| Enterprise | T1027.008 | Stripped PayloadsSub-technique | Cuckoo Stealer is a stripped binary payload.[1] [2] |
| Enterprise | T1140 | Deobfuscate/Decode Files or Information | Cuckoo Stealer strings are deobfuscated prior to execution.[1][2] |
| Enterprise | T1041 | Exfiltration Over C2 Channel | Cuckoo Stealer can send information about the targeted system to C2 including captured passwords, OS build, hostname, and username.[1] |
| Enterprise | T1036.005 | Match Legitimate Resource Name or LocationSub-technique | Cuckoo Stealer has copied and renamed itself to DumpMediaSpotifyMusicConverter.[1][2] |
| Enterprise | T1071.001 | Web ProtocolsSub-technique | Cuckoo Stealer can use the curl API for C2 communications.[1] |
| Enterprise | T1059.004 | Unix ShellSub-technique | Cuckoo Stealer can spawn a bash shell to enable execution on compromised hosts.[1] |
| Enterprise | T1095 | Non-Application Layer Protocol | Cuckoo Stealer can use sockets for communications to its C2 server.[1] |
| Enterprise | T1553.001 | Gatekeeper BypassSub-technique | Cuckoo Stealer can use `xattr -d com.apple.quarantine` to remove the quarantine flag attribute.[1][2] |
| Enterprise | T1543.001 | Launch AgentSub-technique | Cuckoo Stealer can achieve persistence by creating launch agents to repeatedly execute malicious payloads.[1][2] |
| Enterprise | T1059.002 | AppleScriptSub-technique | Cuckoo Stealer can use osascript to generate a password-stealing prompt, duplicate files and folders, and set environmental variables.[1][2] |
| Enterprise | T1555.001 | KeychainSub-technique | Cuckoo Stealer can capture files from a targeted user's keychain directory.[1] |
| Enterprise | T1082 | System Information Discovery | Cuckoo Stealer can gather information about the OS version and hardware on compromised hosts.[1][2] |
| Enterprise | T1056.002 | GUI Input CaptureSub-technique | Cuckoo Stealer has captured passwords by prompting victims with a “macOS needs to access System Settings” GUI window.[1] |
| Enterprise | T1217 | Browser Information Discovery | Cuckoo Stealer can collect bookmarks, cookies, and history from Safari.[1] |
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 1.0 | Current bundle | 5538b763107b… | ||
| 19.1 | 1.0 | Older bundle | 5538b763107b… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]Kandji Cuckoo April 2024
Kohler, A. and Lopez, C. (2024, April 30). Malware: Cuckoo Behaves Like Cross Between Infostealer and Spyware. Retrieved August 20, 2024.
Open source URL - [2]SentinelOne Cuckoo Stealer May 2024
Stokes, P. (2024, May 9). macOS Cuckoo Stealer | Ensuring Detection and Defense as New Samples Rapidly Emerge. Retrieved August 20, 2024.
Open source URL - [3]mitre-attackS1153Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
