Skip to content
Threat Feed
high threat exploited

Potential macOS Privacy Control Bypass via Localhost SCP

Adversaries can exploit the inclusion of sshd in the macOS Full Disk Access list by using localhost-targeted SCP commands to bypass privacy restrictions and access sensitive files.

Adversaries targeting macOS systems may exploit misconfigurations or legitimate administrative accessibility to circumvent system-level privacy protections. Specifically, if the Secure Shell Daemon (sshd) has been granted Full Disk Access (FDA), attackers can leverage it to access restricted files. By executing Secure Copy Protocol (SCP) commands targeting the localhost (127.0.0.1) and disabling host key verification, an attacker can trick the system into using the privileged sshd process to read files that the user-level process would otherwise be denied. This technique has been observed in the wild, notably by malware families like XCSSET, to facilitate the unauthorized collection of sensitive data. Defenders must monitor for suspicious SCP activity that deviates from standard administrative or development workflows, such as those performed by Vagrant or legitimate deployment scripts.

Attack Chain

  1. Attacker gains initial access to a user account on a macOS system.
  2. Attacker confirms the presence of the SSH daemon in the macOS Full Disk Access list (System Settings > Privacy & Security > Full Disk Access).
  3. Attacker identifies a target sensitive file located in a protected directory (e.g., ~/Library/Application Support/ or other restricted paths).
  4. Attacker constructs an SCP command targeting localhost (scp -o StrictHostKeyChecking=no localhost:/path/to/sensitive/file /tmp/staging).
  5. The SCP process initiates a connection to the local sshd, which leverages its FDA privileges to bypass standard file system access controls.
  6. The sensitive file is copied to an attacker-controlled or accessible temporary directory.
  7. Attacker exfiltrates the collected data from the system.

Impact

Successful exploitation allows an unauthorized party to read arbitrary files on the macOS host, bypassing mandatory access controls enforced by the OS. This can lead to the exfiltration of credentials, browser data, configuration files, and other sensitive user information. While the specific number of victims varies, the technique is a known vector for macOS-targeting malware to achieve broader system access and persistent collection capabilities.

Recommendation

Prioritize monitoring of SCP command lines on all managed macOS endpoints.

  • Deploy the provided detection rule to identify local SCP usage with insecure host key checking flags.
  • Audit the 'Full Disk Access' list on critical macOS systems to identify and remove unauthorized binaries, specifically ensuring sshd is not unnecessarily granted broad disk access.
  • Implement endpoint monitoring via an EDR solution to alert on non-standard SCP behavior.
  • Restrict access to sensitive system directories to prevent unauthorized user-level interaction.

Immediate actions

Deploy the Sigma detection rule to monitor for localhost SCP activity

Detection Engineering 48h

Threat Hunt

Search endpoint logs for SCP processes with StrictHostKeyChecking disabled

T1548 high high confidence hunt now

Data: Process creation events

Mitigations

Audit Full Disk Access permissions for sshd

medium_term IT Operations

T1548

Detection coverage 1

Detect Potential Privacy Control Bypass via Localhost Secure Copy

high

Detects the use of SCP to copy files locally by potentially abusing the sshd inclusion in the Full Disk Access list.

sigma tactics: collection, defense_evasion, privilege_escalation techniques: T1005, T1548 sources: process_creation, macos

Detection queries are available on the platform. Get full rules →