Suspicious macOS Calendar File Modification for Persistence
Adversaries may achieve persistence on macOS by modifying calendar (.ics) files to trigger the execution of malicious programs at recurring intervals.
Adversaries targeting macOS systems may leverage the Calendar application to establish persistence. By programmatically modifying .ics calendar files stored within the ~/Library/Calendars/ directory, attackers can configure malicious event triggers that execute unauthorized code or scripts at recurring intervals. This technique exploits the legitimate functionality of macOS to notify users of calendar events, repurposing it as a mechanism for repeated, stealthy execution of malicious payloads. Defenders should monitor for unexpected processes interacting with the Calendar directory, as legitimate calendar management is typically confined to a specific set of system binaries and trusted applications. This threat is particularly relevant for environments where users rely heavily on calendar-based workflows, as the persistence mechanism is difficult to detect through standard user-level inspection of the Calendar interface.
Impact
Successful exploitation allows for long-term persistence on macOS endpoints, enabling the recurring execution of malware, staging of further tools, or beaconing to command-and-control infrastructure. Because the execution is tied to the Calendar database, it can survive reboots and may bypass simple process-based monitoring if the attacker utilizes native or trusted signing identities to modify the files.
Recommendation
Prioritize the deployment of behavioral monitoring for file modifications within the User Library directory.
- Deploy the provided Sigma rule to detect unauthorized process interactions with .ics files in the calendar directory.
- Audit administrative access to the ~/Library/Calendars/ folder to ensure only expected processes perform modifications.
- Investigate alerts by correlating the process path with known baseline activity for the affected endpoint.
- Exclude legitimate third-party calendar sync tools from the detection logic to reduce noise once those binaries are validated.
Immediate actions
Deploy Sigma rule to detect unauthorized .ics file modifications.
Threat Hunt
Search for non-system binaries modifying files under ~/Library/Calendars/.
Data: File integrity logs
Mitigations
Identify and whitelist legitimate third-party calendar software.
False positive management
Detection coverage 1
Detect Suspicious Calendar File Modification
mediumDetects unauthorized processes modifying .ics calendar files, a technique used to establish persistence via event-triggered execution.
Detection queries are available on the platform. Get full rules →