macOS.OSAMiner is a long-running macOS cryptomining malware campaign, likely active since at least 2015, that deploys a Monero miner while using layered run-only AppleScripts to hinder reverse engineering and analysis. It has been associated with trojanized and cracked macOS software, including pirated productivity and gaming applications, as an infection vector.
The malware uses a multi-stage architecture. An initial run-only AppleScript establishes persistence through LaunchAgents, performs environmental checks such as available disk space, drops and executes an embedded anti-analysis AppleScript, and retrieves a subsequent stage from a URL concealed within the source of a public web page. Later variants increased complexity by embedding one run-only AppleScript inside another. Additional stages masquerade as benign file types while functioning as AppleScript or Mach-O payloads.
A notable feature of macOS.OSAMiner is its defense-evasion logic. Its embedded script checks for Activity Monitor and terminates it, and it also searches for consumer security and cleanup tools to interfere with analysis or removal. It further inspects installation logs to identify certain installed applications. The malware also kills Terminal in some execution paths and uses simple anti-virtualization logic by checking CPU characteristics before deploying the miner.
For persistence and execution, macOS.OSAMiner stores components in user-space locations and has adapted its storage strategy over time, shifting from earlier directories to cache locations in response to macOS privacy and access-control changes introduced in Mojave. The miner deployment stage downloads and configures a Monero mining component consistent with XMR-STAK-RX, writes configuration files, prevents the system from sleeping, and launches the miner to consume host resources.
Operationally, infections have been associated with high CPU utilization, system instability, and interference with user attempts to inspect running processes. macOS.OSAMiner is best characterized as a macOS-focused cryptomining trojan with persistence, downloader behavior, and anti-analysis features.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
macOS.OSAMiner has evolved to use a complex architecture, embedding one run-only AppleScript within another... Next, it writes out the embedded AppleScript to ~/Library/k.plist via a do shell script command, and then executes the embedded script with osascript
The malware authors used run-only AppleScripts prevented much further analysis... Recent versions of macOS.OSAMiner add greater complexity by embedding one run-only AppleScript inside another... the script is passed an obfuscated string of hex characters.
Despite the .png extension, it is of course another run-only AppleScript, which is now written out to ~/Library/11.png on the infected device... In keeping with the malware’s tactic of using misleading file extensions, this is of course not a plist but in fact a Mach-O executable.
Observed Parent Script Strings: rm ~/Library/11.png rm ~/Library/k.plist
It parses the output of the built-in system_profiler tool to check whether the device has 4 cores, a rudimentary way of trying to ensure it is not running in a virtual machine environment.
The parent script first checks the disk capacity of the victim’s machine via System Events and exits if there is not enough free space... It parses the output of the built-in system_profiler tool to check whether the device has 4 cores, a rudimentary way of trying to ensure it is not running in a virtual machine environment.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, enumerating PIDs, checking for specific process names, or using APIs such as CreateToolhelp32Snapshot and commands such as tasklist and ps.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
It parses the output of the built-in system_profiler tool to check whether the device has 4 cores, a rudimentary way of trying to ensure it is not running in a virtual machine environment.
The parent script first checks the disk capacity of the victim’s machine via System Events and exits if there is not enough free space... It parses the output of the built-in system_profiler tool to check whether the device has 4 cores, a rudimentary way of trying to ensure it is not running in a virtual machine environment.
downloading the first stage of the miner by retrieving a URL embedded in a public web page... The extracted URL is passed to the curl utility for downloading a remote file... The executable appears to be an instance of the XMR-STAK miner and is downloaded from a hardcoded and obfuscated URL
If found, it passes the application’s name to its ‘kPro’ or ‘killProcess’ handler to prevent the user inspecting resource usage... It searches both for PIDs among running processes and it parses the operating system’s install.log for apps matching its hardcoded list, killing any that it finds along the way.
36 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
macOS.OSAMiner (v1.0→v1.1)
A long-running macOS Monero-mining campaign distributed via trojanized/cracked apps. It uses layered run-only AppleScripts for persistence, staging, and anti-analysis/evasion (e.g., killing Activity Monitor and security/cleanup tools), retrieves additional stages from public web pages, and ultimately downloads/configures a Monero miner payload.
A macOS cryptomining malware campaign distributed via trojanized/cracked apps. It uses layered run-only AppleScripts for persistence, anti-analysis, process killing, staged payload retrieval from public web pages, and deployment of a Monero miner.
Embeds stripped payloads within another run-only stripped payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.