For the complete documentation index, see llms.txt. This page is also available as Markdown.

Uncommon AppleScript designed to access cryptocurrency wallet data was executed via the command line

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

Detector Tags

AppleScript Analytics, Sensitive Information Stealing Analytics

ATT&CK Tactic

Execution (TA0002), Collection (TA0009)

ATT&CK Technique

Command and Scripting Interpreter: AppleScript (T1059.002), Data from Local System (T1005)

Severity

Informational

Description

The AppleScript interpreter was executed with a script designed to access cryptocurrency wallet data.

Attacker's Goals

Exfiltrate cryptocurrency wallet data and seed phrases for direct financial theft.

Investigative actions

  • Identify which cryptocurrency wallet application data was targeted.

  • Check if wallet seed phrases, private keys, or transaction data were accessed.

  • Verify whether the process or its children attempted to exfiltrate the wallet data.

  • Determine if the executing user typically uses cryptocurrency applications.

Variations

Uncommon AppleScript designed to access cryptocurrency wallet data was executed via the command line accessed crypto wallet's files

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002), Collection (TA0009)

ATT&CK Technique

Command and Scripting Interpreter: AppleScript (T1059.002), Data from Local System (T1005)

Severity

Medium

Description

The AppleScript interpreter was executed with a script designed to access cryptocurrency wallet data.

Attacker's Goals

Exfiltrate cryptocurrency wallet data and seed phrases for direct financial theft.

Investigative actions

  • Identify which cryptocurrency wallet application data was targeted.

  • Check if wallet seed phrases, private keys, or transaction data were accessed.

  • Verify whether the process or its children attempted to exfiltrate the wallet data.

  • Determine if the executing user typically uses cryptocurrency applications.

Was this helpful?