Clankerusecase
macOS detection coverage
← Back to main site
Home/ Targets/ macOS

macOS detections

Clankerusecase tracks 78 detection use cases covering the macOS attack surface across 62 MITRE ATT&CK techniques.

Detections targeting macOS endpoints — osascript / launchd / .plist persistence / Mach-O execution.

Open Detection Library → View on the matrix
78Use cases
62Techniques
35Articles
6Kill-chain phases

Top techniques on macOS (25)

Reconnaissance (1)

[LLM] Internet-facing macOS hosts unpatched against the Screen Sharing CVE cluster (exposure hunt) Bespoke recon · hunting DSP

Delivery (11)

[WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Internal delivery · alerting DSPDD [WEEKLY] Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) Internal delivery · alerting DSΣP [LLM] AmnesiaStealer ClickFix loader: macOS shell fetching payload from fake-GitHub / Amnesia C2 host Bespoke delivery · alerting DSΣPCS [LLM] macOS ClickFix: Terminal spawns shell decoding Base64 / curl-pipe payload Bespoke delivery · hunting DSΣPCS [LLM] XCSSET v40 trojanized Xcode build spawning curl-to-shell downloader Bespoke delivery · hunting DSΣPCS [LLM] Malicious @velora-dex/sdk (9.4.1/9.4.2) pulled into GitHub Actions build runner Bespoke delivery · alerting DSΣPDDCS [LLM] Compromised @velora-dex/sdk npm package (9.4.1/9.4.2) installed on CI runner Bespoke delivery · alerting DSΣPDDCS [LLM] node process spawning bash/curl chain to fetch Velora DEX install.sh dropper Bespoke delivery · alerting DSΣPDDCS [LLM] IoliteLabs VSCode extension dropper: VS Code child process reaching rraghh.com / oortt.com C2 Bespoke delivery · alerting DSΣPDD [LLM] npm/node postinstall hook spawning interpreter and reaching new C2 host (Axios-style dropper) Bespoke delivery · hunting DSPDDCS [LLM] Pastebin-piping stager retrieved from rentry.co/openclaw-core (macOS/Linux ClawHub skill) Bespoke delivery · alerting DSPDDCS

Exploitation (18)

[LLM] Inbound Screen Sharing (VNC port 5900) from a public IP to a Mac — CVE-2026-65400 exposure Bespoke exploit · hunting DSΣPCS [LLM] macOS screensharingd spawning a shell or downloader as root (post-exploit RCE) Bespoke exploit · alerting DSΣPCS Article-specific behavioural hunt — ChainDrop: Inside a Self-Propagating npm Worm Bespoke exploit · hunting DSP Article-specific behavioural hunt — Inside the keyv npm Compromise: preinstall Malware, Trusted Provenance, and IDE Bespoke exploit · hunting DSP [LLM] npm/node install-time payload: package manager spawning curl/launchctl/osascript on a runner Bespoke exploit · hunting DSΣPCS Article-specific behavioural hunt — A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope Bespoke exploit · hunting DSP Article-specific behavioural hunt — Pythagora-io/gpt-pilot Compromised on GitHub - Shai-Hulud Credential Stealer Blo Bespoke exploit · hunting DSP Article-specific behavioural hunt — Nx Console VS Code Extension Compromised Bespoke exploit · hunting DSP Article-specific behavioural hunt — Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Published via Compromised Bespoke exploit · hunting DSP Article-specific behavioural hunt — TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromi Bespoke exploit · hunting DSP Article-specific behavioural hunt — TanStack Npm Packages Compromised Inside The Mini Shai Hulud Supply Chain Attack Bespoke exploit · hunting DSP Article-specific behavioural hunt — @velora-dex/sdk Compromised on npm: Malicious Version Drops macOS Backdoor via l Bespoke exploit · hunting DSP Article-specific behavioural hunt — axios Compromised on npm - Malicious Versions Drop Remote Access Trojan Bespoke exploit · hunting DSP Article-specific behavioural hunt — Malicious IoliteLabs VSCode Extensions Target Solidity Developers on Windows, ma Bespoke exploit · hunting DSP Article-specific behavioural hunt — Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT Bespoke exploit · hunting DSP Article-specific behavioural hunt — Harden Runner Now Supports Windows and macOS GitHub Actions Runners Bespoke exploit · hunting DSP Article-specific behavioural hunt — Installing and managing Java on macOS Bespoke exploit · hunting DSP Article-specific behavioural hunt — Using insecure npm package manager defaults to steal your macOS keyboard shortcu Bespoke exploit · hunting DSP

Installation (28)

[WEEKLY] Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) Internal install · alerting DSΣPDD [LLM] Attacker-controlled sudoers policy written under /etc/sudoers.d (CVE-2026-43760 root file-create primitive) Bespoke install · alerting DSΣPCS [LLM] macOS root LaunchDaemon persistence dropped by untrusted process (Apple crash-reporter impersonation) Bespoke install · hunting DSΣPCS [LLM] XCSSET v40 worming: non-IDE process modifying multiple Xcode .pbxproj files Bespoke install · alerting DSPCS [LLM] SleeperGem Unix persistence: cron/systemd/LaunchAgent write by Ruby-descended shell Bespoke install · hunting DSΣPDDCS [LLM] Velora macOS backdoor launchctl persistence (com.apple.Terminal.profiler.plist) Bespoke install · hunting DSΣPCS [LLM] MiniRAT launchctl persistence established during macOS CI build Bespoke install · hunting DSΣPCS [LLM] plain-crypto-js postinstall RAT dropper spawns downloader (axios/Sapphire Sleet) Bespoke install · alerting DSΣPDDCS [LLM] axios RAT dropped artifacts: renamed PowerShell wt.exe + campaign 6202033 files Bespoke install · alerting DSΣPDDCS [LLM] IronWorm cross-platform payload execution by SHA256 (jscrambler stealer binaries) Bespoke install · hunting DSΣPDDCS [LLM] Jackson typosquat Cobalt Strike implant hash sighting (Win + macOS/Linux) Bespoke install · hunting DSΣPDDCS [LLM] easy-day-js implant artifacts dropped: protocal.cjs / NodePackages / cross-OS persistence files Bespoke install · alerting DSΣPDDCS [LLM] macOS.Gaslight LaunchAgent persistence masquerading as com.apple.system.services.activity Bespoke install · alerting DSΣPCS [LLM] macOS.Gaslight self-staged standalone CPython 3.10.18 fetch (astral-sh python-build-standalone) Bespoke install · alerting DSΣPCS [LLM] macOS.Gaslight known-bad file hashes (Mach-O implant, BONZAI sibling, Python/bash stages) Bespoke install · hunting DSΣPCS [LLM] easy-day-js stealer persistence masquerading as Node tooling (NodePackages / LaunchAgent / systemd) Bespoke install · alerting DSΣPDDCS [LLM] macOS LaunchAgent Persistence — com.user.kitty-monitor.plist (Nx Console Compromise) Bespoke install · alerting DSΣPDDCS [LLM] Kitty cat.py Python Backdoor File Drop / Execution (Nx Console Compromise) Bespoke install · alerting DSΣPDDCS [LLM] Mini Shai-Hulud 'gh-token-monitor' persistence daemon (LaunchAgent / systemd) Bespoke install · alerting DSΣPDDCS [LLM] macOS LaunchAgent/LaunchDaemon plist persistence pointing at Python interpreter Bespoke install · hunting DSΣPDDCS [LLM] macOS Python backdoor persistence via kitty-monitor LaunchAgent and cat.py drop Bespoke install · alerting DSΣPDDCS [LLM] launchctl persistence registering zsh.profiler service from non-admin location Bespoke install · alerting DSΣPDDCS [LLM] macOS file write of profiler binary to com.apple.Terminal masquerade path Bespoke install · alerting DSΣPDDCS [LLM] OpenClaw persistence — launchd plist / systemd unit drop referencing 'openclaw' Bespoke install · alerting DSΣPDDCS [LLM] TeamPCP telnyx FetchAudio() — python subprocess running inline base64 exec Bespoke install · alerting DSΣPDD [LLM] macOS Axios RAT daemon spoof + ad-hoc codesign of hidden /private/tmp binary Bespoke install · alerting DSΣPDDCS [LLM] npm postinstall SSH-backdoor chain: node spawning sudo ufw allow 22/tcp + chown ~/.ssh Bespoke install · alerting DSΣPDD [LLM] PTX-Player macOS infostealer artifacts (SHA256 + dropped /private/tmp logs) Bespoke install · hunting DSΣPCS

Command & Control (5)

[LLM] XCSSET v40 Chrome launched with CDP remote-debugging enabled (browser hijack) Bespoke c2 · hunting DSΣPCS [LLM] XCSSET v40 outbound retrieval to rotating C2 module/binary paths (/s/, /d/) Bespoke c2 · hunting DSPCS [LLM] Build runner beacon/exfil to Velora backdoor C2 (89.36.224.5 / datahub.ink) Bespoke c2 · hunting DSΣPDDCS [LLM] macOS.Gaslight Telegram Bot API C2 polling from non-browser process Bespoke c2 · hunting DSΣPCS [LLM] Outbound connection to Velora DEX npm supply-chain C2 89.36.224.5 Bespoke c2 · alerting DSΣPDDCS

Actions on Objectives (15)

[WEEKLY] Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes Internal actions · alerting DSPDD MCP Filesystem Server Suspicious Extension Write ESCU actions · hunting P File Download or Read to Pipe Execution ESCU actions · alerting P MacOS AMOS Stealer - Virtual Machine Check Activity ESCU actions · hunting P MacOS Gatekeeper Bypass ESCU actions · hunting P MacOS Hidden Files and Directories ESCU actions · hunting P MacOS List Firewall Rules ESCU actions · hunting P [LLM] AmnesiaStealer credential harvest: keychain dump, APFS TCC-bypass mount, and fake password prompt Bespoke actions · hunting DSΣPCS [LLM] Monero (XMRig) mining pool egress from a macOS host post-Screen-Sharing compromise Bespoke actions · hunting DSΣPCS [LLM] macOS captured-password validation via dscl authonly + keychain unlock with cleartext password Bespoke actions · hunting DSΣPCS [LLM] macOS browser 'Safe Storage' master-key theft via security find-generic-password Bespoke actions · alerting DSΣPCS [LLM] macOS headless Chromium launched with remote-debugging (CDP browser hijack) Bespoke actions · alerting DSΣPCS [LLM] macOS.Gaslight keychain theft + collected_data.zip staging Bespoke actions · alerting DSΣPCS [LLM] Developer credential store read by Python or Node spawned from VS Code (Nx Console stealer pattern) Bespoke actions · hunting DSPDDCS [LLM] macOS Text Replacements exfiltration via `defaults read NSUserDictionaryReplacementItems` Bespoke actions · alerting DSΣPCS

Recent articles citing macOS-targeted detections