Skip to content
Threat Feed
medium advisory

Python-Based Persistence via macOS Launch Agents and Daemons

Attackers are leveraging Python scripts, compromised dependencies, and insecure model deserialization to establish persistence on macOS by creating malicious LaunchAgent and LaunchDaemon plist files.

Adversaries are increasingly using Python-based execution vectors to establish long-term access on macOS endpoints. By exploiting malicious scripts, vulnerable third-party dependencies, or insecure deserialization routines in machine learning models (such as pickle or PyTorch __reduce__), attackers can force a Python process to write configuration files into the system's LaunchAgent or LaunchDaemon directories.

These plist files configure the operating system to automatically launch malicious payloads upon user login or system boot. Because legitimate administrative tools rarely use Python to create these persistence mechanisms, the first-time occurrence of a Python process performing these file operations is a high-fidelity indicator of potential compromise. This technique is particularly concerning in development or data science environments where frequent loading of untrusted model files or dependencies occurs, as it allows attackers to bypass traditional detection by operating within the context of trusted application frameworks.

Impact

Successful exploitation results in unauthorized persistent access to macOS systems. This allows attackers to maintain command-and-control communication, exfiltrate sensitive data, or deploy further malicious payloads across reboots. This technique primarily impacts organizations using macOS for research, machine learning, or software development, where the use of third-party packages and pre-trained model files is prevalent.

Recommendation

Prioritize the identification of unauthorized persistence mechanisms created by Python processes.

  • Deploy detection logic to flag the creation of LaunchAgent and LaunchDaemon files by python* processes, specifically monitoring for the first occurrence on a per-host basis.
  • Audit all Python-based system management tools (e.g., Ansible, SaltStack) in your environment to create allowlists for legitimate automation workflows.
  • Enforce security scanning for model files (e.g., using tools like Fickling) to detect malicious pickle payloads before execution.
  • If a suspicious plist is identified, use launchctl unload to immediately terminate the persistent process and isolate the host for forensic analysis.

Immediate actions

Deploy the Sigma-compatible rule provided to the endpoint monitoring system.

Detection Engineering 48h

Mitigations

Review and restrict write permissions for LaunchAgent/LaunchDaemon directories on sensitive macOS workstations.

short_term IT Operations

Detection coverage 1

Detect First Time Python Created a LaunchAgent or LaunchDaemon

medium

Detects the first time a Python process creates or modifies a LaunchAgent or LaunchDaemon plist file on a host.

sigma tactics: persistence techniques: T1543.001, T1543.004 sources: process_creation, macos

Detection queries are available on the platform. Get full rules →