Skip to content
Threat Feed
medium advisory

Suspicious macOS Calendar File Modification for Persistence

Adversaries may achieve persistence on macOS by modifying calendar (.ics) files to trigger the execution of malicious programs at recurring intervals.

Adversaries targeting macOS systems may leverage the Calendar application to establish persistence. By programmatically modifying .ics calendar files stored within the ~/Library/Calendars/ directory, attackers can configure malicious event triggers that execute unauthorized code or scripts at recurring intervals. This technique exploits the legitimate functionality of macOS to notify users of calendar events, repurposing it as a mechanism for repeated, stealthy execution of malicious payloads. Defenders should monitor for unexpected processes interacting with the Calendar directory, as legitimate calendar management is typically confined to a specific set of system binaries and trusted applications. This threat is particularly relevant for environments where users rely heavily on calendar-based workflows, as the persistence mechanism is difficult to detect through standard user-level inspection of the Calendar interface.

Impact

Successful exploitation allows for long-term persistence on macOS endpoints, enabling the recurring execution of malware, staging of further tools, or beaconing to command-and-control infrastructure. Because the execution is tied to the Calendar database, it can survive reboots and may bypass simple process-based monitoring if the attacker utilizes native or trusted signing identities to modify the files.

Recommendation

Prioritize the deployment of behavioral monitoring for file modifications within the User Library directory.

  • Deploy the provided Sigma rule to detect unauthorized process interactions with .ics files in the calendar directory.
  • Audit administrative access to the ~/Library/Calendars/ folder to ensure only expected processes perform modifications.
  • Investigate alerts by correlating the process path with known baseline activity for the affected endpoint.
  • Exclude legitimate third-party calendar sync tools from the detection logic to reduce noise once those binaries are validated.

Immediate actions

Deploy Sigma rule to detect unauthorized .ics file modifications.

Detection Engineering 48h

Threat Hunt

Search for non-system binaries modifying files under ~/Library/Calendars/.

T1546 medium medium confidence hunt now

Data: File integrity logs

Mitigations

Identify and whitelist legitimate third-party calendar software.

medium IT Operations

False positive management

Detection coverage 1

Detect Suspicious Calendar File Modification

medium

Detects unauthorized processes modifying .ics calendar files, a technique used to establish persistence via event-triggered execution.

sigma tactics: persistence techniques: T1546 sources: file_event, macos

Detection queries are available on the platform. Get full rules →