Sub-technique of T1569 System Services.View on attack.mitre.org
Adversaries may abuse launchctl to execute commands or programs. Launchctl interfaces with launchd, the service management framework for macOS. Launchctl supports taking subcommands on the command-line, interactively, or even redirected from standard input.
Adversaries use launchctl to execute commands and programs as Launch Agents or Launch Daemons. Common subcommands include: launchctl load,launchctl unload, and launchctl start. Adversaries can use scripts or manually run the commands launchctl load -w "%s/Library/LaunchAgents/%s" or /bin/launchctl load to execute Launch Agents or Launch Daemons.
Rules on DetectionCode tagged with T1569.001.
| Rule | Level | Log source |
|---|---|---|
| Launch Agent/Daemon Execution Via Launchctl | medium | macos / process_creation |
None recorded.
None recorded.
| Used by | Procedure example |
|---|---|
| MalwareAppleJeus | AppleJeus has loaded a plist file using the |
| MalwareCalisto | Calisto uses launchctl to enable screen sharing on the victim’s machine. |
| MalwareCuckoo Stealer | Cuckoo Stealer can use `launchctl` to load a LaunchAgent for persistence. |
| MalwareLoudMiner | LoudMiner launched the QEMU services in the |
| MalwaremacOS.OSAMiner | macOS.OSAMiner has used `launchctl` to restart the Launch Agent. |
| MalwareXCSSET | XCSSET loads a system level launchdaemon using the |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.