Launchctl

T1569.001

Sub-technique of T1569 System Services.View on attack.mitre.org

About this technique

Adversaries may abuse launchctl to execute commands or programs. Launchctl interfaces with launchd, the service management framework for macOS. Launchctl supports taking subcommands on the command-line, interactively, or even redirected from standard input.

Adversaries use launchctl to execute commands and programs as Launch Agents or Launch Daemons. Common subcommands include: launchctl load,launchctl unload, and launchctl start. Adversaries can use scripts or manually run the commands launchctl load -w "%s/Library/LaunchAgents/%s" or /bin/launchctl load to execute Launch Agents or Launch Daemons.

Detection rules1

Rules on DetectionCode tagged with T1569.001.

Sigma1

RuleLevelLog source
Launch Agent/Daemon Execution Via Launchctlmediummacos / process_creation

Splunk0

No Splunk rules are mapped to this technique yet.

Groups0

None recorded.

Software6

Campaigns0

None recorded.

Procedure examples6

Software6

Used byProcedure example
MalwareAppleJeus

AppleJeus has loaded a plist file using the launchctl command.

MalwareCalisto

Calisto uses launchctl to enable screen sharing on the victim’s machine.

MalwareCuckoo Stealer

Cuckoo Stealer can use `launchctl` to load a LaunchAgent for persistence.

MalwareLoudMiner

LoudMiner launched the QEMU services in the /Library/LaunchDaemons/ folder using launchctl. It also uses launchctl to unload all Launch Daemons when updating to a newer version of LoudMiner.

MalwaremacOS.OSAMiner

macOS.OSAMiner has used `launchctl` to restart the Launch Agent.

MalwareXCSSET

XCSSET loads a system level launchdaemon using the launchctl load -w command from /System/Librarby/LaunchDaemons/ssh.plist.

References3

  1. 20 macOS Common Tools and Techniques Open source
    Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved August 23, 2021.
  2. Launchctl Man Open source
    SS64. (n.d.). launchctl. Retrieved March 28, 2020.
  3. Sofacy Komplex Trojan Open source
    Dani Creus, Tyler Halfpop, Robert Falcone. (2016, September 26). Sofacy's 'Komplex' OS X Trojan. Retrieved July 8, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.