MacOS Injection via Third-Party Frameworks
ID: e7b90360-149b-5253-a607-a54ae7876893
STIX ID: report--e7b90360-149b-5253-a607-a54ae7876893
Feed Name: TrustedSec blog
Threat Score
This report details PoC techniques for macOS post-exploitation: leveraging .NET Core’s debug transport named pipes to perform remote process memory read/write and code injection into signed/hardened processes, and abusing Electron’s ELECTRON_RUN_AS_NODE environment variable to execute Node code under a signed app and inherit TCC/privacy permissions (demonstrated by injecting an Apfell implant). The author documents discovery, PoC code, and mitigation-relevant observations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
