Python-Based Persistence via macOS Launch Agents and Daemons
Attackers are leveraging Python scripts, compromised dependencies, and insecure model deserialization to establish persistence on macOS by creating malicious LaunchAgent and LaunchDaemon plist files.
Adversaries are increasingly using Python-based execution vectors to establish long-term access on macOS endpoints. By exploiting malicious scripts, vulnerable third-party dependencies, or insecure deserialization routines in machine learning models (such as pickle or PyTorch __reduce__), attackers can force a Python process to write configuration files into the system's LaunchAgent or LaunchDaemon directories.
These plist files configure the operating system to automatically launch malicious payloads upon user login or system boot. Because legitimate administrative tools rarely use Python to create these persistence mechanisms, the first-time occurrence of a Python process performing these file operations is a high-fidelity indicator of potential compromise. This technique is particularly concerning in development or data science environments where frequent loading of untrusted model files or dependencies occurs, as it allows attackers to bypass traditional detection by operating within the context of trusted application frameworks.
Impact
Successful exploitation results in unauthorized persistent access to macOS systems. This allows attackers to maintain command-and-control communication, exfiltrate sensitive data, or deploy further malicious payloads across reboots. This technique primarily impacts organizations using macOS for research, machine learning, or software development, where the use of third-party packages and pre-trained model files is prevalent.
Recommendation
Prioritize the identification of unauthorized persistence mechanisms created by Python processes.
- Deploy detection logic to flag the creation of LaunchAgent and LaunchDaemon files by
python*processes, specifically monitoring for the first occurrence on a per-host basis. - Audit all Python-based system management tools (e.g., Ansible, SaltStack) in your environment to create allowlists for legitimate automation workflows.
- Enforce security scanning for model files (e.g., using tools like Fickling) to detect malicious pickle payloads before execution.
- If a suspicious plist is identified, use
launchctl unloadto immediately terminate the persistent process and isolate the host for forensic analysis.
Immediate actions
Deploy the Sigma-compatible rule provided to the endpoint monitoring system.
Mitigations
Review and restrict write permissions for LaunchAgent/LaunchDaemon directories on sensitive macOS workstations.
Detection coverage 1
Detect First Time Python Created a LaunchAgent or LaunchDaemon
mediumDetects the first time a Python process creates or modifies a LaunchAgent or LaunchDaemon plist file on a host.
Detection queries are available on the platform. Get full rules →