Plist File Modification

T1647

Technique.View on attack.mitre.org

About this technique

Adversaries may modify property list files (plist files) to enable other malicious activity, while also potentially evading and bypassing system defenses. macOS applications use plist files, such as the info.plist file, to store properties and configuration settings that inform the operating system how to handle the application at runtime. Plist files are structured metadata in key-value pairs formatted in XML based on Apple's Core Foundation DTD. Plist files can be saved in text or binary format.

Adversaries can modify key-value pairs in plist files to influence system behaviors, such as hiding the execution of an application (i.e. Hidden Window) or running additional commands for persistence (ex: Launch Agent/Launch Daemon or Re-opened Applications).

For example, adversaries can add a malicious application path to the `~/Library/Preferences/com.apple.dock.plist` file, which controls apps that appear in the Dock. Adversaries can also modify the LSUIElement key in an application’s info.plist file to run the app in the background. Adversaries can also insert key-value pairs to insert environment variables, such as LSEnvironment, to enable persistence via Dynamic Linker Hijacking.

Detection rules1

Rules on DetectionCode tagged with T1647.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk1

RuleTypeRiskData source
MacOS plutilTTPNULLOsquery Results

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples2

Software2

Used byProcedure example
MalwareCuckoo Stealer

Cuckoo Stealer can create and populate property list (plist) files to enable execution.

MalwareXCSSET

In older versions, XCSSET uses the plutil command to modify the LSUIElement, DFBundleDisplayName, and CFBundleIdentifier keys in the /Contents/Info.plist file to change how XCSSET is visible on the system. In later versions, XCSSET leverages a third-party notarized `dockutil` tool to modify the `.plist` file responsible for presenting applications to the user in the Dock and LaunchPad to point to a malicious application.

References3

  1. eset_osx_flashback Open source
    ESET. (2012, January 1). OSX/Flashback. Retrieved April 19, 2022.
  2. fileinfo plist file description Open source
    FileInfo.com team. (2019, November 26). .PLIST File Extension. Retrieved October 12, 2021.
  3. wardle chp2 persistence Open source
    Patrick Wardle. (2022, January 1). The Art of Mac Malware Volume 0x1:Analysis. Retrieved April 19, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.