Detection of macOS Persistence via Hidden Plist Filenames
Adversaries establish persistence on macOS by registering launch agents or daemons using dot-prefixed property list files to evade detection by hiding configuration artifacts.
Adversaries targeting macOS systems frequently leverage the BackgroundTaskManagement subsystem to maintain persistence. By installing a launch agent or launch daemon with a property list (plist) filename starting with a dot (e.g., .com.malicious.plist), attackers can effectively hide these configuration files from default directory listings. This technique combines persistence mechanisms with defense evasion, as the files remain functional while avoiding casual discovery by users or administrators.
Defenders can identify this activity by monitoring registration messages generated by the macOS BackgroundTaskManagement subsystem. These logs contain metadata such as the plist path, item type, and the target executable path. This detection capability is critical for identifying malicious background tasks that attempt to masquerade as legitimate system services.
Impact
Successful implementation of this technique allows for persistent execution of malicious code at user login or system boot. If unmitigated, this enables long-term access, potential exfiltration of sensitive data, and further lateral movement within an organization. This technique has been observed in advanced macOS spyware such as CloudMensis, highlighting its role in espionage operations.
Recommendation
Detection engineering teams should focus on implementing telemetry collection for macOS BackgroundTaskManagement events and creating specific alerts for dot-prefixed plist registrations.
- Enable the macOS Security Events integration to collect BackgroundTaskManagement logs.
- Deploy detection logic to monitor for plist paths within
/Library/LaunchAgents/or/Library/LaunchDaemons/that match the regex pattern/\..*\.plist$. - Investigate any alert that identifies non-signed executables or executables located in user-writable directories.
- Use
launchctl bootoutto remediate identified malicious launch items once confirmed.
Immediate actions
Deploy monitoring for dot-prefixed plist registration events in macOS Security Events telemetry.
Threat Hunt
Audit existing LaunchAgents and LaunchDaemons directories for dot-prefixed plist files.
Data: Filesystem listing of /Library/LaunchAgents and /Library/LaunchDaemons