Launch Daemon

T1543.004

Sub-technique of T1543 Create or Modify System Process.View on attack.mitre.org

About this technique

Adversaries may create or modify Launch Daemons to execute malicious payloads as part of persistence. Launch Daemons are plist files used to interact with Launchd, the service management framework used by macOS. Launch Daemons require elevated privileges to install, are executed for every user on a system prior to login, and run in the background without the need for user interaction. During the macOS initialization startup, the launchd process loads the parameters for launch-on-demand system-level daemons from plist files found in /System/Library/LaunchDaemons/ and /Library/LaunchDaemons/. Required Launch Daemons parameters include a Label to identify the task, Program to provide a path to the executable, and RunAtLoad to specify when the task is run. Launch Daemons are often used to provide access to shared resources, updates to software, or conduct automation tasks.

Adversaries may install a Launch Daemon configured to execute at startup by using the RunAtLoad parameter set to true and the Program parameter set to the malicious executable path. The daemon name may be disguised by using a name from a related operating system or benign software (i.e. Masquerading). When the Launch Daemon is executed, the program inherits administrative permissions.

Additionally, system configuration changes (such as the installation of third party package managing software) may cause folders such as usr/local/bin to become globally writeable. So, it is possible for poor configurations to allow an adversary to modify executables referenced by current Launch Daemon's plist files.

Detection rules2

Rules on DetectionCode tagged with T1543.004.

Sigma2

RuleLevelLog source
Potential Persistence Via PlistBuddyhighmacos / process_creation
Launch Agent/Daemon Execution Via Launchctlmediummacos / process_creation

Splunk0

No Splunk rules are mapped to this technique yet.

Groups0

None recorded.

Software10

Campaigns1

Procedure examples11

Software10

Used byProcedure example
MalwareAppleJeus

AppleJeus has placed a plist file within the LaunchDaemons folder and launched it manually.

MalwareBundlore

Bundlore can persist via a LaunchDaemon.

MalwareCOATHANGER

COATHANGER will create a daemon for timed check-ins with command and control infrastructure.

MalwareDacls

Dacls can establish persistence via a Launch Daemon.

MalwareGreen Lambert

Green Lambert can add a plist file in the `Library/LaunchDaemons` to establish persistence.

MalwareLoudMiner

LoudMiner adds plist files with the naming format com.[random_name].plist in the /Library/LaunchDaemons folder with the RunAtLoad and KeepAlive keys set to true.

MalwareOSX_OCEANLOTUS.D

If running with root permissions, OSX_OCEANLOTUS.D can create a persistence file in the folder /Library/LaunchDaemons.

MalwareREPTILE

The REPTILE launcher can daemonize a process.

View all 10 software examples

Campaigns1

Used byProcedure example
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus installs a Launch Daemon to execute the POOLRAT macOS backdoor software.

References7

  1. AppleDocs Launch Agent Daemons Open source
    Apple. (n.d.). Creating Launch Daemons and Agents. Retrieved July 10, 2017.
  2. LaunchDaemon Hijacking Open source
    Bradley Kemp. (2021, May 10). LaunchDaemon Hijacking: privilege escalation and persistence via insecure folder permissions. Retrieved July 26, 2021.
  3. Methods of Mac Malware Persistence Open source
    Patrick Wardle. (2014, September). Methods of Malware Persistence on Mac OS X. Retrieved July 5, 2017.
  4. OSX Malware Detection Open source
    Patrick Wardle. (2016, February 29). Let's Play Doctor: Practical OS X Malware Detection & Analysis. Retrieved November 17, 2024.
  5. WireLurker Open source
    Claud Xiao. (n.d.). WireLurker: A New Era in iOS and OS X Malware. Retrieved July 10, 2017.
  6. launchd Keywords for plists Open source
    Dennis German. (2020, November 20). launchd Keywords for plists. Retrieved October 7, 2021.
  7. sentinelone macos persist Jun 2019 Open source
    Stokes, Phil. (2019, June 17). HOW MALWARE PERSISTS ON MACOS. Retrieved September 10, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.