Launch Agent

T1543.001

Sub-technique of T1543 Create or Modify System Process.View on attack.mitre.org

About this technique

Adversaries may create or modify launch agents to repeatedly execute malicious payloads as part of persistence. When a user logs in, a per-user launchd process is started which loads the parameters for each launch-on-demand user agent from the property list (.plist) file found in /System/Library/LaunchAgents, /Library/LaunchAgents, and ~/Library/LaunchAgents. Property list files use the Label, ProgramArguments , and RunAtLoad keys to identify the Launch Agent's name, executable location, and execution time. Launch Agents are often installed to perform updates to programs, launch user specified programs at login, or to conduct other developer tasks.

Launch Agents can also be executed using the Launchctl command.

Adversaries may install a new Launch Agent that executes at login by placing a .plist file into the appropriate folders with the RunAtLoad or KeepAlive keys set to true. The Launch Agent name may be disguised by using a name from the related operating system or benign software. Launch Agents are created with user level privileges and execute with user level permissions.

Detection rules4

Rules on DetectionCode tagged with T1543.001.

Sigma2

RuleLevelLog source
Potential Persistence Via PlistBuddyhighmacos / process_creation
Launch Agent/Daemon Execution Via Launchctlmediummacos / process_creation

Splunk2

RuleTypeRiskData source
Suspicious PlistBuddy UsageTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Suspicious PlistBuddy Usage via OSqueryTTPNULLOsquery Results

Groups1

Software22

Campaigns0

None recorded.

Procedure examples23

Groups1

Used byProcedure example
GroupContagious Interview

Contagious Interview has established persistence using InvisibleFerret malware to create file to run the script on Startup via LaunchAgents. Contagious Interview has also utilized a plist file located in `/Library/LaunchAgents` to enable a malicious bash script the ability to persist.

Software22

Used byProcedure example
MalwareBundlore

Bundlore can persist via a LaunchAgent.

MalwareCalisto

Calisto adds a .plist file to the /Library/LaunchAgents folder to maintain persistence.

MalwareCoinTicker

CoinTicker creates user launch agents named .espl.plist and com.apple.[random string].plist to establish persistence.

MalwareCookieMiner

CookieMiner has installed multiple new Launch Agents in order to maintain persistence for cryptocurrency mining software.

MalwareCrossRAT

CrossRAT creates a Launch Agent on macOS.

MalwareCuckoo Stealer

Cuckoo Stealer can achieve persistence by creating launch agents to repeatedly execute malicious payloads.

MalwareDacls

Dacls can establish persistence via a LaunchAgent.

MalwareDok

Dok installs two LaunchAgents to redirect all network traffic with a randomly generated name for each plist file maintaining the format com.random.name.plist.

View all 22 software examples

References8

  1. Antiquated Mac Malware Open source
    Thomas Reed. (2017, January 18). New Mac backdoor using antiquated code. Retrieved July 5, 2017.
  2. AppleDocs Launch Agent Daemons Open source
    Apple. (n.d.). Creating Launch Daemons and Agents. Retrieved July 10, 2017.
  3. Methods of Mac Malware Persistence Open source
    Patrick Wardle. (2014, September). Methods of Malware Persistence on Mac OS X. Retrieved July 5, 2017.
  4. OSX Keydnap malware Open source
    Marc-Etienne M.Leveille. (2016, July 6). New OSX/Keydnap malware is hungry for credentials. Retrieved July 3, 2017.
  5. OSX Malware Detection Open source
    Patrick Wardle. (2016, February 29). Let's Play Doctor: Practical OS X Malware Detection & Analysis. Retrieved November 17, 2024.
  6. OSX.Dok Malware Open source
    Thomas Reed. (2017, July 7). New OSX.Dok malware intercepts web traffic. Retrieved July 10, 2017.
  7. OceanLotus for OS X Open source
    Eddie Lee. (2016, February 17). OceanLotus for OS X - an Application Bundle Pretending to be an Adobe Flash Update. Retrieved July 5, 2017.
  8. Sofacy Komplex Trojan Open source
    Dani Creus, Tyler Halfpop, Robert Falcone. (2016, September 26). Sofacy's 'Komplex' OS X Trojan. Retrieved July 8, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.