Skip to content
Threat Feed
high advisory

Persistence via macOS Shell Profile Curl Execution

Threat actors achieve persistence on macOS by injecting curl commands into shell profile scripts to execute malicious payloads automatically upon user login or terminal initialization.

Threat actors utilize macOS shell configuration files, including .zshrc, .bashrc, .bash_profile, and .zprofile, as a persistence mechanism to maintain access and facilitate secondary payload delivery. By injecting commands into these scripts, attackers ensure that malicious logic is executed every time a user initiates a shell session or logs into the system. This method is particularly effective for beaconing and downloading follow-on stages of an attack. Defenders should monitor for unexpected curl activity originating from child processes of shells that were invoked by login processes. This activity creates a reliable mechanism that persists across system reboots and provides attackers with a consistent execution window.

Attack Chain

  1. Attacker gains initial access to the target macOS system.
  2. Attacker identifies a user shell profile script, such as ~/.zshrc or ~/.bash_profile, to modify.
  3. Attacker injects a malicious curl command with download flags (e.g., -o, -F) into the selected shell profile file.
  4. The user logs into the system or opens a new terminal window.
  5. The login process spawns a shell (bash, zsh, or sh).
  6. The shell parses the modified configuration file and executes the injected curl command.
  7. The curl command reaches out to the attacker's C2 server to download secondary payloads or beacons.
  8. The downloaded payload executes on the endpoint, completing the persistence or command-and-control cycle.

Impact

Successful exploitation allows for long-term persistence on macOS endpoints, enabling attackers to maintain command-and-control access, exfiltrate data, or deploy secondary malware. Because these scripts run with the privileges of the user, attackers can access sensitive environment variables, tokens, and files accessible to the user, potentially escalating their impact within the organization.

Recommendation

  1. Deploy the provided Sigma rule to detect suspicious curl execution following a login-initiated shell event.
  2. Perform periodic audits of user shell profiles (.zshrc, .bashrc, .bash_profile) to identify unauthorized modifications.
  3. Review file modification timestamps on critical configuration files to detect the timing of potential persistence establishment.
  4. Block known malicious domains at the network perimeter if identified through endpoint analysis of downloaded artifacts.
  5. Reset compromised user shell profiles from known-good backups or standard organizational templates.

Immediate actions

Deploy Sigma detection rule to environment

Detection Engineering 48h

Threat Hunt

Search shell configuration files for curl or wget commands

T1546.004 medium high confidence hunt now

Data: File integrity monitoring or host-based file search

Mitigations

Remove unauthorized curl entries from shell profile scripts

short_term IT Operations

T1546.004

Gaps

  • Lack of historical data on existing persistent configuration entries

Detection coverage 1

Detect Curl Execution via Shell Profile

high

Detects when curl is executed via a shell profile upon login, indicating potential persistence or malicious payload delivery.

sigma tactics: command_and_control, persistence techniques: T1105, T1546.004 sources: process_creation, macos

Detection queries are available on the platform. Get full rules →