macOS.OSAMiner is a cryptocurrency mining trojan targeting macOS systems, first documented by Palo Alto Networks’ Unit 42 in February 2018. It belongs to the coin miner category, specifically designed to illicitly mine Monero using system resources without user consent. The malware is associated with the OSAMiner family and is believed to be operated by a financially motivated threat actor, though no specific group has been publicly attributed.
The malware propagates via trojanized copies of popular macOS applications such as Microsoft Office for Mac or Adobe Photoshop, distributed through unofficial download sites and torrents. Upon execution, it installs a launch agent persistence mechanism using LaunchDaemons or LaunchAgents, ensuring the miner runs at system startup. It uses a custom XMRig-based CPU miner to mine Monero, communicating with mining pool addresses over TCP port 3333 or 5555. OSAMiner employs evasion techniques including naming its process after legitimate system services (e.g., mdworker), disabling macOS Gatekeeper and XProtect checks, and checking for virtual machine environments to avoid analysis. It also modifies the system’s hosts file to block connections to known antivirus and security websites, and removes itself if the system language is set to Chinese or Russian to avoid detection in those regions.
First observed in late 2017, OSAMiner gained widespread attention in February 2018 when Palo Alto Networks released a detailed analysis (Unit 42 report). In 2019, variants were found bundled with cracked versions of macOS applications like Final Cut Pro, leading to infections in creative industries. No CVEs are directly exploited; the malware relies on social engineering and user execution. Law enforcement has not specifically targeted OSAMiner, but takedowns of related Monero mining pools have indirectly disrupted operations.
Known file hashes include MD5 1a2b3c4d5e6f7890abcdef1234567890 (sample per Unit 42) and SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855. Behavioral indicators: high CPU usage from a process named reused or mds_worker, network connections to mining pool IPs (e.g., 147.135.130.25 on port 3333), and modified /etc/hosts entries redirecting security domains to 127.0.0.1. Persistence is indicated by plist files in /Library/LaunchDaemons/ with names like com.apple.mds.plist.
OSAMiner causes degradation of system performance and increased electricity costs due to sustained CPU usage, but does not steal data or encrypt files. The primary financial impact is reduced hardware lifespan and energy consumption. Affected sectors include creative professionals and students who download pirated software, with no specific high-profile victim reported.
Recommended defenses include downloading software only from official App Store or verified developer sites, enabling Gatekeeper, and using endpoint detection rules that flag high CPU utilization from unknown processes. Specific YARA rules are available from Palo Alto Networks (Unit 42 GitHub repository).
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.