logo

Restoring Dyld Memory Loading

ID: 695b4bee-e508-5fe8-bc10-ab924ea64568

STIX ID: report--695b4bee-e508-5fe8-bc10-ab924ea64568

Feed Name: XPN Infosec Blog

Threat Score
65/100

Date Published: 2023-01-14

Date Updated: 2026-07-30

...
...

This blog post explains how recent macOS/dyld behavior persists Mach-O bundles created via NSCreateObjectFileImageFromMemory to temporary files and demonstrates a technique to intercept dyld (patching the mmap/pread/fcntl service calls) and mock I/O so a malicious or red-team payload can be kept in memory or have on-disk reads dynamically swapped; the write-up includes ARM64 patching details, sample hooking and mock implementations, caveats about code-signing/entitlements on Apple Silicon, and practical PoC notes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.