Skip to content
Threat Feed
medium advisory

Detection of macOS Persistence via Hidden Plist Filenames

Adversaries establish persistence on macOS by registering launch agents or daemons using dot-prefixed property list files to evade detection by hiding configuration artifacts.

Adversaries targeting macOS systems frequently leverage the BackgroundTaskManagement subsystem to maintain persistence. By installing a launch agent or launch daemon with a property list (plist) filename starting with a dot (e.g., .com.malicious.plist), attackers can effectively hide these configuration files from default directory listings. This technique combines persistence mechanisms with defense evasion, as the files remain functional while avoiding casual discovery by users or administrators.

Defenders can identify this activity by monitoring registration messages generated by the macOS BackgroundTaskManagement subsystem. These logs contain metadata such as the plist path, item type, and the target executable path. This detection capability is critical for identifying malicious background tasks that attempt to masquerade as legitimate system services.

Impact

Successful implementation of this technique allows for persistent execution of malicious code at user login or system boot. If unmitigated, this enables long-term access, potential exfiltration of sensitive data, and further lateral movement within an organization. This technique has been observed in advanced macOS spyware such as CloudMensis, highlighting its role in espionage operations.

Recommendation

Detection engineering teams should focus on implementing telemetry collection for macOS BackgroundTaskManagement events and creating specific alerts for dot-prefixed plist registrations.

  • Enable the macOS Security Events integration to collect BackgroundTaskManagement logs.
  • Deploy detection logic to monitor for plist paths within /Library/LaunchAgents/ or /Library/LaunchDaemons/ that match the regex pattern /\..*\.plist$.
  • Investigate any alert that identifies non-signed executables or executables located in user-writable directories.
  • Use launchctl bootout to remediate identified malicious launch items once confirmed.

Immediate actions

Deploy monitoring for dot-prefixed plist registration events in macOS Security Events telemetry.

Detection Engineering 48h

Threat Hunt

Audit existing LaunchAgents and LaunchDaemons directories for dot-prefixed plist files.

T1564.001 medium high confidence hunt now

Data: Filesystem listing of /Library/LaunchAgents and /Library/LaunchDaemons