Cisco Talos Unveils “Living-off-the-Land” Tactics Threatening macOS
ID: e57dda26-fe66-50d9-b729-869a0a983098
STIX ID: report--e57dda26-fe66-50d9-b729-869a0a983098
Feed Name: securityonline.info
Cisco Talos warns that as macOS adoption rises in enterprises—particularly on developer and DevOps machines—attackers increasingly abuse native macOS features for stealthy LOTL operations (e.g., hiding payloads in Spotlight metadata, using RAS for remote execution, weaponizing SNMP and socat for file transfers and command execution), enabling bypasses of traditional static-file defenses; the report demonstrates techniques and recommends process-lineage monitoring, IPC anomaly detection, and strict MDM policies to reduce risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
