{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/persistence-mechanism/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["macos","persistence","persistence-mechanism"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eAdversaries targeting macOS environments may abuse the Finder Sync plugin feature to achieve persistence. Finder Sync plugins are legitimate components designed to extend the Finder's functionality and modify the user interface. By registering a rogue plugin, an attacker can ensure their malicious code is executed repeatedly by the system. This activity is typically performed via the 'pluginkit' command-line utility, which is used to manage system extensions. Monitoring the invocation of 'pluginkit' with specific arguments, especially when triggered by unauthorized parent processes or processes lacking valid code signatures, is a key detection strategy for security teams. This technique allows attackers to persist across reboots and user logons by masquerading as legitimate UI extensions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for long-term persistence on macOS endpoints, facilitating ongoing command and control, data exfiltration, or the deployment of secondary malicious payloads. The impact is limited to the local system unless the plugin facilitates further lateral movement or privilege escalation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eDeploy EDR-based detection to monitor the execution of the 'pluginkit' binary.\u003c/li\u003e\n\u003cli\u003eBaseline authorized Finder Sync plugins in your environment to distinguish them from rogue registrations.\u003c/li\u003e\n\u003cli\u003eInvestigate parent process lineage for all 'pluginkit' executions, prioritizing alerts triggered by script interpreters like 'python', 'node', or 'osascript'.\u003c/li\u003e\n\u003cli\u003ePerform periodic audits of registered plugins using the 'pluginkit -m' command to identify unauthorized or unexpected extensions.\u003c/li\u003e\n\u003cli\u003eEnforce code signing policies for applications deployed to enterprise macOS endpoints.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-28T21:07:28Z","date_published":"2026-08-28T21:07:28Z","id":"https://feed.craftedsignal.io/briefs/2026-08-macos-finder-sync-persistence/","summary":"Adversaries leverage the macOS Finder Sync plugin mechanism to maintain persistence by using the 'pluginkit' utility to register and enable malicious extensions.","title":"Abuse of macOS Finder Sync Plugins for Persistence","url":"https://feed.craftedsignal.io/briefs/2026-08-macos-finder-sync-persistence/"}],"language":"en","title":"CraftedSignal Threat Feed - Persistence-Mechanism","version":"https://jsonfeed.org/version/1.1"}