Detection of Suspicious macOS Launch Item Registration
Adversaries leverage macOS launch agent and daemon registration to establish persistence by executing binaries from temporary or world-writable directories to evade standard security monitoring.
Adversaries targeting macOS environments often establish persistence by registering malicious launch agents or launch daemons. These components are defined by property list (plist) files which specify a target executable to run upon system or user startup. To avoid detection, threat actors frequently stage these malicious executables within temporary, world-writable, or user-accessible directories such as /tmp, /var/tmp, /var/folders, /Users/Shared, or specific user-level cache and download directories.
Legitimate software typically resides in protected system or application paths. By identifying launch items that point to suspicious locations, security teams can detect non-standard persistence mechanisms used by malware, such as the CloudMensis spyware, to maintain long-term access. Monitoring the BackgroundTaskManagement (BTM) subsystem logs allows for visibility into the registration of these items, providing a critical defensive measure against unauthorized background process execution.
Attack Chain
- An attacker gains initial access to the macOS endpoint.
- The attacker stages a malicious payload (executable binary) into a temporary or world-writable directory (e.g., /tmp/malware).
- The attacker crafts a malicious property list (plist) file pointing to the staged binary path.
- The attacker triggers the registration of the launch item using launchctl or the BTM subsystem.
- The macOS BackgroundTaskManagement subsystem records the registration, including the plist path and the target executable path.
- The system automatically executes the binary from the temporary location upon next user login or system reboot.
- The malware achieves persistence, enabling ongoing malicious operations on the target host.
Impact
Successful exploitation allows attackers to maintain persistence on macOS systems, facilitating ongoing espionage, exfiltration of sensitive data, or delivery of secondary payloads. Unauthorized background processes running with user or system privileges can bypass standard user-space restrictions, potentially leading to full host compromise.
Recommendation
Deploy detection rules targeting the registration of launch agents and daemons with executables residing in non-standard paths.
- Enable the macOS Security Events integration to collect BackgroundTaskManagement logs.
- Implement the provided rule to alert on launch items referencing temporary or user-writable directories.
- Investigate any triggered alerts by analyzing the origin of the executable and the lifecycle of the associated plist file.
- Perform manual reviews of persistent launch items that reside outside of /Applications or /System directories.
Immediate actions
Deploy the suspicious launch item detection rule.
Threat Hunt
Search for existing launch items referencing /tmp, /var/tmp, or /Users/Shared in existing BTM logs.
Data: macOS Security Events integration logs
Detection coverage 1
Detect Suspicious macOS Launch Item Registration
mediumDetects the registration of a launch agent or daemon pointing to an executable in a suspicious or user-writable path.
Detection queries are available on the platform. Get full rules →