Huntbase Hub · All hunts

Threat hunts for macOS

41 hunts covering macOS, each with a hypothesis, the queries that test it and what the hunt cannot see.

41 hunts

  1. medium Part 2 of 2
    Research by Elastic Security Labs

    Administrative AI Configuration File Tampering

    An adversary has modified system-wide AI configuration files or hooks on a Linux endpoint to bypass security constraints or establish persistence outside the managed reconciliation workflow.

    3 query1 analytic1 checkpoint1 action2 task
    discovery · execution · persistence
  2. medium Part 1 of 2
    Research by Elastic Security Labs

    Automated EDR Response Action Reconciliation

    An adversary has compromised a management principal or repurposed an Elastic workflow to perform mass remote execution across the Linux fleet, masquerading as a legitimate configuration reconciliation loop.

    5 query2 analytic1 checkpoint1 action2 task
    discovery · execution · persistence
  3. high Part 2 of 2
    Research by Sekoia

    ErrTraffic ClickFix PowerShell and Infostealer Activity

    An intruder has tricked a user into running a PowerShell command via a ClickFix lure, which downloads an infostealer to harvest credentials and connect to blockchain-resolved C2 domains.

    3 query1 analytic1 checkpoint1 action2 task
    collection · command and control · credential access
  4. high Part 1 of 2
    Research by Sekoia

    ErrTraffic Infrastructure and Delivery Monitoring

    An intruder has compromised WordPress servers to host the ErrTraffic framework, which currently resolves C2 via blockchain RPCs and serves ClickFix lures from specific JavaScript endpoints.

    4 query1 analytic1 checkpoint1 action2 task
    collection · command and control · credential access
  5. high Part 2 of 2
    Research by Cisco Talos

    Amatera Stealer and Follow-on Payloads

    An intruder has deployed the Amatera stealer, characterized by DLL hollowing of dbghelp.dll and dead-drop C2 resolution via Telegraph, and is now scanning for cryptocurrency wallets or deploying secondary payloads like ZigCryptoStealer.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  6. high Part 2 of 2
    Research by Cisco Talos

    Host Intrusion and Destructive Impact

    An adversary has bypassed local security controls using system patchers and is executing AI-generated scripts to perform mass file encryption for ransomware extortion.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · execution · impact
  7. high Part 1 of 2
    Research by Cisco Talos

    Remote access abuse and red-team implants

    An intruder accessed the environment via an external remote service using a single-factor credential and deployed red-team framework implants to maintain command and control.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · execution · impact
  8. high Part 2 of 2
    Research by Sekoia

    ChocoPoC: Mapbox Dead-Drop C2 and Exfiltration

    An adversary is using trojanised Python packages to establish C2 via DoH and Mapbox datasets on researcher workstations, subsequently exfiltrating credentials from local password stores.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2025-55182 · CVE-2025-64446
  9. high
    Research by Elastic Security Labs

    Rapid Phishing and Proxy-based Exfiltration

    An adversary has bypassed phishing-resistant MFA to gain initial access via a SaaS provider and is now using a multi-hop proxy or tunnel to exfiltrate data from an internal host.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · exfiltration · initial access
  10. high
    Research by Elastic Security Labs

    Living off the coding agent: Tunnels and LaunchAgents

    An adversary is using a signed coding agent to proxy shell execution, establish reverse tunnels for service exposure, and install LaunchAgent persistence on a developer workstation.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  11. medium
    Research by Elastic Security Labs

    Endpoint-to-Cloud Phased Intrusion Hunt

    An adversary establishes a beachhead on an endpoint, moves laterally to obtain administrative access, and pivots to cloud services while maintaining C2 via a multi-hop proxy.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  12. medium
    Research by Elastic Security Labs

    Vulnerable Driver Exploitation and Kernel Escalation

    An adversary has exploited a public-facing application to stage and load a vulnerable kernel driver, bypassing security controls to gain persistent high-integrity access to the host.

    4 query2 analytic2 checkpoint1 action2 task
    execution · initial access · privilege escalation
  13. high Part 2 of 2
    Research by Unit 42

    Appliance Persistence and Identity Abuse

    An adversary has modified appliance scheduled tasks to disable MFA and is exfiltrating credentials via native Slack webhook integrations.

    3 query1 analytic1 checkpoint1 action2 task
    defense evasion · execution · exfiltration
  14. high Part 1 of 2
    Research by Unit 42

    Collaboration Platform Phishing and Execution

    An intruder has compromised an enterprise identity using collaboration tools to bypass email-based controls and execute malicious code via sideloading or malicious dependencies.

    4 query2 analytic2 checkpoint1 action2 task
    defense evasion · execution · exfiltration
  15. high
    Research by Unit 42

    Commodity Loader and Multi-Payload PPI Activity

    An intruder is using trojanised installers to deploy a multi-stage loader that beacons to rotational C2 domains and installs follow-on backdoors like Insomnia RAT and ARKTunnel.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · execution · initial access
  16. high
    Research by Red Canary

    Entra ID Agent User Impersonation and Teams Abuse

    An attacker uses the Entra ID Agent User OAuth flow to impersonate an AI agent and dispatch malicious content via Microsoft Teams using Graph API cmdlets.

    3 query1 analytic1 checkpoint1 action2 task
    execution · initial access
  17. high Part 1 of 2
    Research by Sekoia

    ErrTraffic: WordPress Infrastructure and Backdoor Maintenance

    An adversary has compromised a WordPress server using harvested credentials and installed a PHP backdoor or malicious plugin to facilitate the delivery of ErrTraffic ClickFix lures.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  18. high
    Research by Elastic Security Labs

    Bypass of npm Cooldown and Dependency Compromise

    An intruder or developer removes the npm cooldown setting to bypass a mandatory waiting period for new packages, enabling the installation of a compromised dependency.

    3 query1 analytic1 checkpoint1 action2 task
    defense evasion · initial access
  19. high Part 2 of 2
    Research by Huntress

    MacSync Binary Persistence and Application Tampering

    An adversary has established long-term persistence on a macOS host by installing a Mach-O RAT via a custom LaunchAgent and is using specialized capture agents to bypass TCC permissions and phish for crypto wallet recovery phrases.

    5 query1 analytic1 checkpoint1 action2 task
    collection · credential access · execution
  20. high Part 1 of 2
    Research by Huntress

    MacSync Scripted Execution and Credential Theft

    An attacker has deployed MacSync Stealer on a macOS host by tricking a user into executing a curl-to-zsh one-liner, which then runs in-memory scripts to harvest credentials and keychains.

    4 query2 analytic2 checkpoint1 action2 task
    collection · credential access · execution
  21. high Part 2 of 2
    Research by Huntress

    Malicious C2 Infrastructure Polling

    An intruder is communicating with AMOS or NetSupport RAT infrastructure through DNS lookups, direct socket connections, or specific HTTP paths, often utilizing processes running from temporary directories.

    5 query1 analytic1 checkpoint1 action2 task
    collection · command and control · execution
  22. high Part 1 of 2
    Research by Huntress

    Cross-Platform Malware Execution and Persistence

    An intruder has compromised endpoints via a fake Google Doc lure, leading to user-driven execution of AMOS or NetSupport RAT loaders followed by persistence and credential staging.

    3 query2 analytic2 checkpoint1 action2 task
    collection · command and control · execution
  23. high Part 2 of 2
    Research by Huntress

    AI-Impersonation Driven Script Execution and Data Theft

    An intruder uses a trusted AI platform to trick a user into executing a terminal command from the clipboard, establishing persistence and stealing credentials.

    4 query2 analytic2 checkpoint1 action2 task
    credential access · execution · initial access
  24. high Part 1 of 2
    Research by Huntress

    AI Platform Mediated Malvertising and Redirection

    An intruder is abusing trusted AI platforms such as Claude or ChatGPT to host malicious redirection lures via SEO poisoning, funnelling users from legitimate AI domains to secondary malware delivery infrastructure.

    4 query1 analytic1 checkpoint1 action2 task
    credential access · execution · initial access
  25. high Part 2 of 2
    Research by Unit 42

    ChainDrop Worm: Developer Tooling Persistence and Supply Chain Propagation

    An adversary has compromised developer environments by injecting malicious hooks into IDE configuration files, using automated GitHub workflows to propagate an npm worm and resolve C2 via Ethereum smart contracts.

    4 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  26. high Part 1 of 2
    Research by Unit 42

    ChainDrop: NPM Worm Endpoint and CI Runner Activity

    An intruder has infected an npm package and triggered a preinstall hook that uses the Bun runtime to harvest credentials from the filesystem and CI runner process memory.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  27. high Part 3 of 3
    Research by Datadog Security Labs

    Shai-Hulud: Exfiltration and Deadman Switch

    An attacker is using the Shai-Hulud framework to exfiltrate stolen credentials through GitHub dead-drops and has installed a destructive deadman switch that triggers a home-directory wipe if tokens are revoked.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  28. high Part 2 of 3
    Research by Datadog Security Labs

    Shai-Hulud Secret Harvesting and Discovery

    An intruder has deployed the Shai-Hulud framework to extract credentials from filesystem paths and process memory, subsequently using them to automate the discovery of cloud and Kubernetes infrastructure secrets.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · discovery
  29. high Part 1 of 3
    Research by Datadog Security Labs

    Shai-Hulud Framework Supply Chain Hook and Loader Bootstrap

    The adversary poisons a developer repository or AI coding assistant configuration to execute the Shai-Hulud loader and establish daemonized persistence.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · discovery
  30. medium
    Research by Elastic Security Labs

    Suspicious ingress tool transfer via native utilities

    An adversary is using native Linux or macOS utilities like curl or wget to download malicious payloads from external infrastructure, hiding their activity within the high volume of legitimate cloud automation.

    3 query1 analytic1 checkpoint1 action2 task
    command and control
  31. medium
    Research by Elastic Security Labs

    AI Coding Agent Tool-Call Auditing

    An AI agent operating under developer credentials is executing rare shell commands, accessing sensitive configuration files, or communicating with third-party MCP servers without explicit developer intent.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · discovery · execution
  32. high
    Research by Red Canary

    Entra ID Assistive Agent Impersonation

    An adversary has gained initial access by tricking a user into consenting to an assistive agent blueprint, then used an on-behalf-of flow to execute malicious Graph API actions from a macOS-based PowerShell environment.

    5 query2 analytic1 checkpoint1 action2 task
    credential access · execution · exfiltration
  33. medium
    Research by Elastic Security Labs

    Threat Intelligence Lifecycle Detection

    An intruder has exploited a vulnerable service or leveraged phishing to gain a beachhead, followed by multi-hop proxy C2 communication and subsequent mass file modification or resource hijacking.

    6 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · impact
  34. high Part 2 of 2
    Research by Unit 42

    AMOS Stealer C2 and Exfiltration Patterns

    An adversary exfiltrates keychain, browser, and wallet data from macOS hosts by sending a sequence of HTTP POST requests containing specific stage parameters to malicious infrastructure.

    3 query1 analytic1 checkpoint1 action2 task
    collection · command and control · execution
  35. high Part 1 of 2
    Research by Unit 42

    Atomic macOS (AMOS) Stealer Activity

    An adversary has compromised a macOS host using deceptive Terminal setup commands to execute encoded shell scripts, establishing hidden persistence in Application Support and staging harvested data in temporary directories.

    5 query2 analytic1 checkpoint1 action2 task
    collection · command and control · execution
  36. high Part 2 of 2
    Research by Proofpoint

    UNK_DeadDrop Credential and Crypto Wallet Theft

    A developer has cloned a malicious repository that executed an Overlord-derived RAT to steal browser credentials and cryptocurrency wallets before cleaning up its own files.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  37. high Part 2 of 2
    Research by Cisco Talos

    VoidLink Lateral Scanning and Mesh C2

    An intruder is using a VoidLink implant to perform automated internal reconnaissance and establish a peer-to-peer mesh command-and-control network between compromised Linux servers.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · discovery · execution
  38. high Part 1 of 2
    Research by Cisco Talos

    VoidLink: Exploitation and Kernel-Level Implant Deployment

    An adversary has exploited a Java-based Apache Dubbo service to deploy a ZigLang-based VoidLink implant and maintained stealth using an unsigned kernel-level rootkit.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · discovery · execution
  39. high
    Research by Ossprey

    Flutter Supply Chain Build Execution

    An adversary has compromised developer and CI environments by injecting malicious Flutter packages that execute obfuscated shell scripts during native Android or iOS builds.

    4 query2 analytic2 checkpoint1 action2 task
    command and control · execution · initial access
  40. high Part 2 of 2
    Research by Elastic Security Labs

    CHAINDROP: C2 Discovery and Worm Propagation

    An attacker has infected local development environments via trojanized npm packages and is using Ethereum smart contracts to discover C2 infrastructure before propagating the worm using stolen GitHub credentials.

    4 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  41. high Part 1 of 2
    Research by Elastic Security Labs

    CHAINDROP: Host-Based Node.js Worm Execution and Harvesting

    An attacker has gained initial access through a backdoored npm package preinstall hook, which executes a dropper to install a rogue Bun runtime and harvest developer credentials from local IDE configurations.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · execution