Researchers linked multiple macOS cryptomining campaigns to trojanized application installers that launched legitimate apps as decoys while silently deploying Monero miners and persistence mechanisms. SentinelLabs detailed macOS.OSAMiner, an operation active since at least 2015 that spread through cracked or trojanized macOS software, used run-only AppleScripts to obstruct analysis, and fetched later-stage payloads from URLs concealed in public web pages. Earlier reporting on OSX/CreativeUpdater described a similar distribution model through malicious MacUpdate download links for apps such as Firefox, OnyX, and Deeper, where signed disk images bypassed Gatekeeper and installed a miner after opening the real application.
The malware established persistence with LaunchAgents, stored components in user library paths such as ~/Library/Caches/com.apple.XX/ and ~/Library/mdworker/, and deployed Monero mining software including builds based on XMR-STAK-RX and MinerGate. SentinelLabs said the campaign also used anti-analysis and evasion logic, including an embedded AppleScript that killed Activity Monitor, checked for security and cleanup tools such as Avast, Avira, CleanMyMac, Keeper, Lemon, and MacMgr, and used caffeinate plus basic virtual-machine checks to keep mining active. Apple later revoked an abused Developer ID certificate and MacUpdate removed the malicious links tied to the CreativeUpdater distribution chain.

Pull IOCs and campaign context straight into your stack.
8 events from the most recent confirmed update back to the earliest known activity.
In early February 2018, attackers distributed trojanized macOS applications including Firefox, OnyX, and Deeper through malicious download links on MacUpdate. The signed apps bypassed Gatekeeper, launched the legitimate app as a decoy, and installed persistent Monero-mining malware.
On February 1, 2018, a MacUpdate editor account named "Jess-MacUpdate" added comments on several popular applications that were associated with the malicious distribution campaign.
Reports about the malware later identified as macOS.OSAMiner surfaced on Chinese security sites in 2018, describing a Monero-mining trojan affecting macOS users.
SentinelLabs assessed that the macOS.OSAMiner cryptomining malware campaign had likely been circulating since at least 2015.
SentinelLabs released its AEVT decompiler as open source to help analyze malicious run-only AppleScripts such as those used by macOS.OSAMiner.
SentinelLabs combined a public AppleScript disassembler with its AEVT decompiler to statically reverse previously opaque macOS.OSAMiner samples, revealing the malware's multi-stage architecture, persistence, evasion, and miner deployment workflow.
MacUpdate stated that it removed the malicious links used in the CreativeUpdater campaign, reducing the likelihood of further infections through the same vector.
Apple revoked the Developer ID certificate used to sign the malicious CreativeUpdater disk images and applications, disrupting that distribution method.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 43 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
labs.sentinelone.com
Open sourcedigitasecurity.com
Open sourcevirustotal.com
Open sourcevirustotal.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.