Uncommon AppleScript designed to access cryptocurrency wallet data was executed via the command line
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
AppleScript Analytics, Sensitive Information Stealing Analytics
ATT&CK Tactic
Execution (TA0002), Collection (TA0009)
ATT&CK Technique
Command and Scripting Interpreter: AppleScript (T1059.002), Data from Local System (T1005)
Severity
Informational
Description
The AppleScript interpreter was executed with a script designed to access cryptocurrency wallet data.
Attacker's Goals
Exfiltrate cryptocurrency wallet data and seed phrases for direct financial theft.
Investigative actions
Identify which cryptocurrency wallet application data was targeted.
Check if wallet seed phrases, private keys, or transaction data were accessed.
Verify whether the process or its children attempted to exfiltrate the wallet data.
Determine if the executing user typically uses cryptocurrency applications.
Variations
Was this helpful?
