Analytics BIOC Informational

Uncommon AppleScript designed to access cryptocurrency wallet data was executed via the command line

The AppleScript interpreter was executed with a script designed to access cryptocurrency wallet data.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Execution (TA0002) Collection (TA0009)
ATT&CK techniques: Command and Scripting Interpreter: AppleScript (T1059.002) Data from Local System (T1005)
Detector tags: AppleScript Analytics Sensitive Information Stealing Analytics
Attacker's goals:

Exfiltrate cryptocurrency wallet data and seed phrases for direct financial theft.

Investigative actions:

Identify which cryptocurrency wallet application data was targeted. Check if wallet seed phrases, private keys, or transaction data were accessed. Verify whether the process or its children attempted to exfiltrate the wallet data. Determine if the executing user typically uses cryptocurrency applications.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Uncommon AppleScript designed to access cryptocurrency wallet data was executed via the command line accessed crypto wallet's files Medium (parent: Informational)