Malware · 163 giorni fa
macOS is no longer a niche endpoint, and attackers can use its built-in tools to move and execute without tripping the controls many teams rely on. The standard response of watching for suspicious binaries or SSH activity misses the point: native features can be repurposed for stealthy execution, persistence, and lateral movement.
Cisco Talos documents abuse of Remote Application Scripting, Spotlight metadata, and built-in protocols including SMB, Netcat, Git, TFTP, and SNMP. The research says these paths can operate outside standard SSH-based telemetry, which matters because macOS is now common in developer, DevOps, and admin fleets that hold source code, cloud access, and production credentials.
The forward risk is a monitoring gap, not a new exploit. Teams that only key on file scanning or SSH logs will miss movement that looks like normal platform behavior unless they track process lineage and IPC anomalies.
2 fonti che coprono questa storia
MacOS Native Tools Enable Stealthy Enterprise Attacks
macOS LOTL techniques bypass detection using native tools and metadata abuse
Bad Apples: Weaponizing native macOS primitives for movement and execution
Cisco Talos documents several macOS living-off-the-land (LOTL) techniques, demonstrating that native pathways for movement and execution remain accessible to those who understand the underlying architecture.
Part of the PlainSec briefing for 2026-04-22