CoinTicker is a macOS malware family associated with cryptocurrency-themed activity. It has been documented using hidden, dot-prefixed artifacts and LaunchAgent-based persistence to reduce user visibility and maintain execution across logins. The malware stages concealed files in temporary and user-library locations, creates user LaunchAgents including masquerading names that resemble Apple components, and stores additional payload material in hidden container-style directories.
CoinTicker also uses OpenSSL to decode or decrypt an initially downloaded hidden encoded file as part of its execution chain, indicating staged payload handling and defense-evasion tradecraft. It has been observed using curl to retrieve secondary payloads, a delivery and execution pattern that can bypass some macOS trust controls when quarantine metadata is not applied. In addition, CoinTicker executes a bash script to establish a reverse shell, providing remote post-compromise access.
The malware targets macOS systems and combines hidden-file staging, shell-based execution, payload decoding, persistence, and remote shell functionality. Its observed behavior aligns with post-exploitation activity focused on stealthy foothold establishment and continued operator access on compromised Apple endpoints.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Numerous entries state malware can create a remote shell or reverse shell, for example 4H RAT, BLACKCOFFEE, DarkComet, PlugX, QuasarRAT, and others.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
macOS malware family referenced as leveraging curl-based secondary payload delivery to evade Gatekeeper quarantine checks.
A macOS application that installs backdoors under the guise of a cryptocurrency ticker.
Malware that decodes an initially downloaded hidden encoded file using OpenSSL.
Malware that decodes an initially downloaded hidden encoded file using OpenSSL.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.