Threat hunts for macOS
41 hunts covering macOS, each with a hypothesis, the queries that test it and what the hunt cannot see.
41 hunts
-
medium Part 2 of 2Research by Elastic Security Labs
Administrative AI Configuration File Tampering
An adversary has modified system-wide AI configuration files or hooks on a Linux endpoint to bypass security constraints or establish persistence outside the managed reconciliation workflow.
3 query1 analytic1 checkpoint1 action2 taskdiscovery · execution · persistence -
medium Part 1 of 2Research by Elastic Security Labs
Automated EDR Response Action Reconciliation
An adversary has compromised a management principal or repurposed an Elastic workflow to perform mass remote execution across the Linux fleet, masquerading as a legitimate configuration reconciliation loop.
5 query2 analytic1 checkpoint1 action2 taskdiscovery · execution · persistence -
high Part 2 of 2Research by Sekoia
ErrTraffic ClickFix PowerShell and Infostealer Activity
An intruder has tricked a user into running a PowerShell command via a ClickFix lure, which downloads an infostealer to harvest credentials and connect to blockchain-resolved C2 domains.
3 query1 analytic1 checkpoint1 action2 taskcollection · command and control · credential access -
high Part 1 of 2Research by Sekoia
ErrTraffic Infrastructure and Delivery Monitoring
An intruder has compromised WordPress servers to host the ErrTraffic framework, which currently resolves C2 via blockchain RPCs and serves ClickFix lures from specific JavaScript endpoints.
4 query1 analytic1 checkpoint1 action2 taskcollection · command and control · credential access -
high Part 2 of 2Research by Cisco Talos
Amatera Stealer and Follow-on Payloads
An intruder has deployed the Amatera stealer, characterized by DLL hollowing of dbghelp.dll and dead-drop C2 resolution via Telegraph, and is now scanning for cryptocurrency wallets or deploying secondary payloads like ZigCryptoStealer.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 2 of 2Research by Cisco Talos
Host Intrusion and Destructive Impact
An adversary has bypassed local security controls using system patchers and is executing AI-generated scripts to perform mass file encryption for ransomware extortion.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · execution · impact -
high Part 1 of 2Research by Cisco Talos
Remote access abuse and red-team implants
An intruder accessed the environment via an external remote service using a single-factor credential and deployed red-team framework implants to maintain command and control.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · execution · impact -
high Part 2 of 2Research by Sekoia
ChocoPoC: Mapbox Dead-Drop C2 and Exfiltration
An adversary is using trojanised Python packages to establish C2 via DoH and Mapbox datasets on researcher workstations, subsequently exfiltrating credentials from local password stores.
3 query1 analytic1 checkpoint1 action2 taskCVE-2025-55182 · CVE-2025-64446 -
highResearch by Elastic Security Labs
Rapid Phishing and Proxy-based Exfiltration
An adversary has bypassed phishing-resistant MFA to gain initial access via a SaaS provider and is now using a multi-hop proxy or tunnel to exfiltrate data from an internal host.
3 query2 analytic2 checkpoint1 action2 taskcommand and control · exfiltration · initial access -
highResearch by Elastic Security Labs
Living off the coding agent: Tunnels and LaunchAgents
An adversary is using a signed coding agent to proxy shell execution, establish reverse tunnels for service exposure, and install LaunchAgent persistence on a developer workstation.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · execution -
mediumResearch by Elastic Security Labs
Endpoint-to-Cloud Phased Intrusion Hunt
An adversary establishes a beachhead on an endpoint, moves laterally to obtain administrative access, and pivots to cloud services while maintaining C2 via a multi-hop proxy.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · execution -
mediumResearch by Elastic Security Labs
Vulnerable Driver Exploitation and Kernel Escalation
An adversary has exploited a public-facing application to stage and load a vulnerable kernel driver, bypassing security controls to gain persistent high-integrity access to the host.
4 query2 analytic2 checkpoint1 action2 taskexecution · initial access · privilege escalation -
high Part 2 of 2Research by Unit 42
Appliance Persistence and Identity Abuse
An adversary has modified appliance scheduled tasks to disable MFA and is exfiltrating credentials via native Slack webhook integrations.
3 query1 analytic1 checkpoint1 action2 taskdefense evasion · execution · exfiltration -
high Part 1 of 2Research by Unit 42
Collaboration Platform Phishing and Execution
An intruder has compromised an enterprise identity using collaboration tools to bypass email-based controls and execute malicious code via sideloading or malicious dependencies.
4 query2 analytic2 checkpoint1 action2 taskdefense evasion · execution · exfiltration -
highResearch by Unit 42
Commodity Loader and Multi-Payload PPI Activity
An intruder is using trojanised installers to deploy a multi-stage loader that beacons to rotational C2 domains and installs follow-on backdoors like Insomnia RAT and ARKTunnel.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · execution · initial access -
highResearch by Red Canary
Entra ID Agent User Impersonation and Teams Abuse
An attacker uses the Entra ID Agent User OAuth flow to impersonate an AI agent and dispatch malicious content via Microsoft Teams using Graph API cmdlets.
3 query1 analytic1 checkpoint1 action2 taskexecution · initial access -
high Part 1 of 2Research by Sekoia
ErrTraffic: WordPress Infrastructure and Backdoor Maintenance
An adversary has compromised a WordPress server using harvested credentials and installed a PHP backdoor or malicious plugin to facilitate the delivery of ErrTraffic ClickFix lures.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · execution -
highResearch by Elastic Security Labs
Bypass of npm Cooldown and Dependency Compromise
An intruder or developer removes the npm cooldown setting to bypass a mandatory waiting period for new packages, enabling the installation of a compromised dependency.
3 query1 analytic1 checkpoint1 action2 taskdefense evasion · initial access -
high Part 2 of 2Research by Huntress
MacSync Binary Persistence and Application Tampering
An adversary has established long-term persistence on a macOS host by installing a Mach-O RAT via a custom LaunchAgent and is using specialized capture agents to bypass TCC permissions and phish for crypto wallet recovery phrases.
5 query1 analytic1 checkpoint1 action2 taskcollection · credential access · execution -
high Part 1 of 2Research by Huntress
MacSync Scripted Execution and Credential Theft
An attacker has deployed MacSync Stealer on a macOS host by tricking a user into executing a curl-to-zsh one-liner, which then runs in-memory scripts to harvest credentials and keychains.
4 query2 analytic2 checkpoint1 action2 taskcollection · credential access · execution -
high Part 2 of 2Research by Huntress
Malicious C2 Infrastructure Polling
An intruder is communicating with AMOS or NetSupport RAT infrastructure through DNS lookups, direct socket connections, or specific HTTP paths, often utilizing processes running from temporary directories.
5 query1 analytic1 checkpoint1 action2 taskcollection · command and control · execution -
high Part 1 of 2Research by Huntress
Cross-Platform Malware Execution and Persistence
An intruder has compromised endpoints via a fake Google Doc lure, leading to user-driven execution of AMOS or NetSupport RAT loaders followed by persistence and credential staging.
3 query2 analytic2 checkpoint1 action2 taskcollection · command and control · execution -
high Part 2 of 2Research by Huntress
AI-Impersonation Driven Script Execution and Data Theft
An intruder uses a trusted AI platform to trick a user into executing a terminal command from the clipboard, establishing persistence and stealing credentials.
4 query2 analytic2 checkpoint1 action2 taskcredential access · execution · initial access -
high Part 1 of 2Research by Huntress
AI Platform Mediated Malvertising and Redirection
An intruder is abusing trusted AI platforms such as Claude or ChatGPT to host malicious redirection lures via SEO poisoning, funnelling users from legitimate AI domains to secondary malware delivery infrastructure.
4 query1 analytic1 checkpoint1 action2 taskcredential access · execution · initial access -
high Part 2 of 2Research by Unit 42
ChainDrop Worm: Developer Tooling Persistence and Supply Chain Propagation
An adversary has compromised developer environments by injecting malicious hooks into IDE configuration files, using automated GitHub workflows to propagate an npm worm and resolve C2 via Ethereum smart contracts.
4 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · execution -
high Part 1 of 2Research by Unit 42
ChainDrop: NPM Worm Endpoint and CI Runner Activity
An intruder has infected an npm package and triggered a preinstall hook that uses the Bun runtime to harvest credentials from the filesystem and CI runner process memory.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · execution -
high Part 3 of 3Research by Datadog Security Labs
Shai-Hulud: Exfiltration and Deadman Switch
An attacker is using the Shai-Hulud framework to exfiltrate stolen credentials through GitHub dead-drops and has installed a destructive deadman switch that triggers a home-directory wipe if tokens are revoked.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 2 of 3Research by Datadog Security Labs
Shai-Hulud Secret Harvesting and Discovery
An intruder has deployed the Shai-Hulud framework to extract credentials from filesystem paths and process memory, subsequently using them to automate the discovery of cloud and Kubernetes infrastructure secrets.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · discovery -
high Part 1 of 3Research by Datadog Security Labs
Shai-Hulud Framework Supply Chain Hook and Loader Bootstrap
The adversary poisons a developer repository or AI coding assistant configuration to execute the Shai-Hulud loader and establish daemonized persistence.
3 query2 analytic2 checkpoint1 action2 taskcommand and control · credential access · discovery -
mediumResearch by Elastic Security Labs
Suspicious ingress tool transfer via native utilities
An adversary is using native Linux or macOS utilities like curl or wget to download malicious payloads from external infrastructure, hiding their activity within the high volume of legitimate cloud automation.
3 query1 analytic1 checkpoint1 action2 taskcommand and control -
mediumResearch by Elastic Security Labs
AI Coding Agent Tool-Call Auditing
An AI agent operating under developer credentials is executing rare shell commands, accessing sensitive configuration files, or communicating with third-party MCP servers without explicit developer intent.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · discovery · execution -
highResearch by Red Canary
Entra ID Assistive Agent Impersonation
An adversary has gained initial access by tricking a user into consenting to an assistive agent blueprint, then used an on-behalf-of flow to execute malicious Graph API actions from a macOS-based PowerShell environment.
5 query2 analytic1 checkpoint1 action2 taskcredential access · execution · exfiltration -
mediumResearch by Elastic Security Labs
Threat Intelligence Lifecycle Detection
An intruder has exploited a vulnerable service or leveraged phishing to gain a beachhead, followed by multi-hop proxy C2 communication and subsequent mass file modification or resource hijacking.
6 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · impact -
high Part 2 of 2Research by Unit 42
AMOS Stealer C2 and Exfiltration Patterns
An adversary exfiltrates keychain, browser, and wallet data from macOS hosts by sending a sequence of HTTP POST requests containing specific stage parameters to malicious infrastructure.
3 query1 analytic1 checkpoint1 action2 taskcollection · command and control · execution -
high Part 1 of 2Research by Unit 42
Atomic macOS (AMOS) Stealer Activity
An adversary has compromised a macOS host using deceptive Terminal setup commands to execute encoded shell scripts, establishing hidden persistence in Application Support and staging harvested data in temporary directories.
5 query2 analytic1 checkpoint1 action2 taskcollection · command and control · execution -
high Part 2 of 2Research by Proofpoint
UNK_DeadDrop Credential and Crypto Wallet Theft
A developer has cloned a malicious repository that executed an Overlord-derived RAT to steal browser credentials and cryptocurrency wallets before cleaning up its own files.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · defense evasion -
high Part 2 of 2Research by Cisco Talos
VoidLink Lateral Scanning and Mesh C2
An intruder is using a VoidLink implant to perform automated internal reconnaissance and establish a peer-to-peer mesh command-and-control network between compromised Linux servers.
3 query1 analytic1 checkpoint1 action2 taskcommand and control · discovery · execution -
high Part 1 of 2Research by Cisco Talos
VoidLink: Exploitation and Kernel-Level Implant Deployment
An adversary has exploited a Java-based Apache Dubbo service to deploy a ZigLang-based VoidLink implant and maintained stealth using an unsigned kernel-level rootkit.
3 query2 analytic2 checkpoint1 action2 taskcommand and control · discovery · execution -
highResearch by Ossprey
Flutter Supply Chain Build Execution
An adversary has compromised developer and CI environments by injecting malicious Flutter packages that execute obfuscated shell scripts during native Android or iOS builds.
4 query2 analytic2 checkpoint1 action2 taskcommand and control · execution · initial access -
high Part 2 of 2Research by Elastic Security Labs
CHAINDROP: C2 Discovery and Worm Propagation
An attacker has infected local development environments via trojanized npm packages and is using Ethereum smart contracts to discover C2 infrastructure before propagating the worm using stolen GitHub credentials.
4 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · execution -
high Part 1 of 2Research by Elastic Security Labs
CHAINDROP: Host-Based Node.js Worm Execution and Harvesting
An attacker has gained initial access through a backdoored npm package preinstall hook, which executes a dropper to install a rogue Bun runtime and harvest developer credentials from local IDE configurations.
3 query2 analytic2 checkpoint1 action2 taskcommand and control · credential access · execution