According to security firm SentinelOne, users have been targeted by a sneaky malware campaign for more than five years. The campaign used a clever trick (run-only AppleScripts) to evade detection and aimed to mine cryptocurrency macOS systems victims'

Researchers said the malware used in the campaign is called OSAMiner and has been distributed since at least 2015, through pirated (cracked) games and software, such as League of Legends and Microsoft Office for Mac.
“OSAMiner has been active for a long time and has evolved in recent months,” a SentinelOne spokesperson told ZDNet.
“From the data we have, it appears to be primarily targeting communities in China and the Asia-Pacific region,” the spokesperson added.
Run-only AppleScripts to avoid detection
As we said above, the cryptominer has been distributed since at least 2015. However, according to SentinelOne, two Chinese security firms detected and analyzed older versions of OSAMiner in August and September 2018, respectively.
Their reports, however, were incomplete, identifying only a few of OSAMiner's capabilities. This was partly due to the fact that the researchers were unable to recover the entire malware code at the time.
After installing the pirated software, the boobytrapped installers download and execute a run-only AppleScript, which downloads and executes a second run-only AppleScript, and then a third.

Since “run-only” AppleScript is in a state where the source code is not human-readable, analyzing the cryptominer is even more difficult.
A SentinelOne researcher has published details of the attack, along with indicators of compromise (IOCs) from older and newer OSAMiner campaigns. The research team hopes that by breaking the mystery surrounding this campaign and publishing IOCs, other security will be able to detect OSAMiner attacks and protect users .
“Run-only AppleScripts are surprisingly rare in the world of macOS malware, but both the duration (5 years) and the lack of attention to the OSAMiner campaign show just how powerful run-only AppleScripts are in avoiding detection and analysis,” the researcher concluded.
“In this case, we didn't see the attacker using any of the more powerful AppleScript capabilities we've discussed elsewhere. However, it's a threat that remains potent because many defense tools can't handle it.“.
Source: ZDNet
