Sub-technique of T1543 Create or Modify System Process.View on attack.mitre.org
Adversaries may create or modify launch agents to repeatedly execute malicious payloads as part of persistence. When a user logs in, a per-user launchd process is started which loads the parameters for each launch-on-demand user agent from the property list (.plist) file found in /System/Library/LaunchAgents, /Library/LaunchAgents, and ~/Library/LaunchAgents. Property list files use the Label, ProgramArguments , and RunAtLoad keys to identify the Launch Agent's name, executable location, and execution time. Launch Agents are often installed to perform updates to programs, launch user specified programs at login, or to conduct other developer tasks.
Launch Agents can also be executed using the Launchctl command.
Adversaries may install a new Launch Agent that executes at login by placing a .plist file into the appropriate folders with the RunAtLoad or KeepAlive keys set to true. The Launch Agent name may be disguised by using a name from the related operating system or benign software. Launch Agents are created with user level privileges and execute with user level permissions.
Rules on DetectionCode tagged with T1543.001.
| Rule | Level | Log source |
|---|---|---|
| Potential Persistence Via PlistBuddy | high | macos / process_creation |
| Launch Agent/Daemon Execution Via Launchctl | medium | macos / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Suspicious PlistBuddy Usage | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Suspicious PlistBuddy Usage via OSquery | TTP | NULL | Osquery Results |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupContagious Interview | Contagious Interview has established persistence using InvisibleFerret malware to create file to run the script on Startup via LaunchAgents. Contagious Interview has also utilized a plist file located in `/Library/LaunchAgents` to enable a malicious bash script the ability to persist. |
| Used by | Procedure example |
|---|---|
| MalwareBundlore | Bundlore can persist via a LaunchAgent. |
| MalwareCalisto | Calisto adds a .plist file to the /Library/LaunchAgents folder to maintain persistence. |
| MalwareCoinTicker | CoinTicker creates user launch agents named .espl.plist and com.apple.[random string].plist to establish persistence. |
| MalwareCookieMiner | CookieMiner has installed multiple new Launch Agents in order to maintain persistence for cryptocurrency mining software. |
| MalwareCrossRAT | CrossRAT creates a Launch Agent on macOS. |
| MalwareCuckoo Stealer | Cuckoo Stealer can achieve persistence by creating launch agents to repeatedly execute malicious payloads. |
| MalwareDacls | Dacls can establish persistence via a LaunchAgent. |
| MalwareDok | Dok installs two LaunchAgents to redirect all network traffic with a randomly generated name for each plist file maintaining the format |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.