Real-world descriptions of how a group, tool or campaign used a technique.
22 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1543.001 Launch Agent |
MalwareInvisibleFerret | InvisibleFerret has established persistence using LaunchAgents on macOS that run on Startup using a file named “com.avatar.update.wake.plist”. |
| T1543.001 Launch Agent |
MalwaremacOS.OSAMiner | macOS.OSAMiner has placed a Stripped Payloads with a `plist` extension in the Launch Agent's folder. |
| T1543.001 Launch Agent |
MalwareNETWIRE | NETWIRE can use launch agents for persistence. |
| T1543.001 Launch Agent |
MalwareDacls | Dacls can establish persistence via a LaunchAgent. |
| T1543.001 Launch Agent |
MalwareCuckoo Stealer | Cuckoo Stealer can achieve persistence by creating launch agents to repeatedly execute malicious payloads. |
| T1543.001 Launch Agent |
MalwareFruitFly | FruitFly persists via a Launch Agent. |
| T1543.001 Launch Agent |
MalwareKeydnap | Keydnap uses a Launch Agent to persist. |
| T1543.001 Launch Agent |
MalwareGreen Lambert | Green Lambert can create a Launch Agent with the `RunAtLoad` key-value pair set to |
| T1543.001 Launch Agent |
MalwareThiefQuest | ThiefQuest installs a launch item using an embedded encrypted launch agent property list template. The plist file is installed in the |
| T1543.001 Launch Agent |
MalwareBundlore | Bundlore can persist via a LaunchAgent. |
| T1543.001 Launch Agent |
MalwareGlassWorm | GlassWorm has established persistence on macOS via a LaunchAgent by writing a plist under `/library/LaunchAgents`. |
| T1543.001 Launch Agent |
MalwareCrossRAT | CrossRAT creates a Launch Agent on macOS. |
| T1543.001 Launch Agent |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D can create a persistence file in the folder |
| T1543.001 Launch Agent |
MalwareCalisto | Calisto adds a .plist file to the /Library/LaunchAgents folder to maintain persistence. |
| T1543.001 Launch Agent |
MalwareMacMa | MacMa installs a `com.apple.softwareupdate.plist` file in the `/LaunchAgents` folder with the `RunAtLoad` value set to `true`. Upon user login, MacMa is executed from `/var/root/.local/softwareupdate` with root privileges. Some variations also include the `LimitLoadToSessionType` key with the value `Aqua`, ensuring the MacMa only runs when there is a logged in GUI user. |
| T1543.001 Launch Agent |
MalwareProton | Proton persists via Launch Agent. |
| T1543.001 Launch Agent |
MalwareCoinTicker | CoinTicker creates user launch agents named .espl.plist and com.apple.[random string].plist to establish persistence. |
| T1543.001 Launch Agent |
MalwareCookieMiner | CookieMiner has installed multiple new Launch Agents in order to maintain persistence for cryptocurrency mining software. |
| T1543.001 Launch Agent |
MalwareKomplex | The Komplex trojan creates a persistent launch agent called with |
| T1543.001 Launch Agent |
MalwareDok | Dok installs two LaunchAgents to redirect all network traffic with a randomly generated name for each plist file maintaining the format |
| T1543.001 Launch Agent |
MalwareMacSpy | MacSpy persists via a Launch Agent. |
| T1543.001 Launch Agent |
MalwareMini Shai-Hulud | Mini Shai-Hulud has established persistence on macOS hosts by installing a gh-token-monitor daemon through LaunchAgent that polls GitHub every 60 seconds. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.