OSX/CreativeUpdater is a macOS cryptomining trojan that was distributed in early 2018 through trojanized application downloads linked from MacUpdate. The campaign replaced or redirected downloads for legitimate macOS software, including popular utilities and browsers, to attacker-controlled signed disk images and application bundles. Because the malicious packages were signed with a valid Apple Developer ID, they could bypass Gatekeeper in default configurations and appear trustworthy to users.
The trojanized application acted as a wrapper around the legitimate software. When launched, it executed an embedded script while opening the real application as a decoy to reduce suspicion. The script then downloaded and installed a persistent secondary payload into the user’s Library directory and configured LaunchAgent-based persistence so the malware would execute automatically at login.
The installed payload was identified as a renamed MinerGate command-line miner configured to mine Monero using the victim system’s CPU resources. The malware also had update capability through retrieval of additional LaunchAgent or payload components, but there was no confirmed evidence that it deployed functionality beyond cryptocurrency mining in observed cases. Its primary impact was unauthorized resource consumption and persistent compromise of affected Macs rather than espionage, ransomware, or destructive activity.
OSX/CreativeUpdater is notable less for technical sophistication than for its abuse of a trusted software distribution channel and valid code signing to maximize infection potential among macOS users.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
OSX/CreativeUpdater is a macOS cryptominer trojan that was distributed via trojanized applications on MacUpdate. It installs a persistent Monero (XMR) cryptominer (minergate-cli) on infected systems, using launch agents for persistence and masquerading as legitimate applications. The malware is not particularly sophisticated but leverages social engineering and supply chain compromise to infect users.
A macOS trojanized-app campaign distributed via compromised MacUpdate download links for apps such as Firefox, OnyX, and Deeper. The fake app launches a decoy legitimate application, downloads a secondary payload into ~/Library/mdworker, installs LaunchAgents for persistence, and runs a Monero miner on infected systems.
OSX/CreativeUpdater is a trojan that persistently installs itself on macOS systems to mine cryptocurrency.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.