Restoring Dyld Memory Loading
ID: 695b4bee-e508-5fe8-bc10-ab924ea64568
STIX ID: report--695b4bee-e508-5fe8-bc10-ab924ea64568
Feed Name: XPN Infosec Blog
This blog post explains how recent macOS/dyld behavior persists Mach-O bundles created via NSCreateObjectFileImageFromMemory to temporary files and demonstrates a technique to intercept dyld (patching the mmap/pread/fcntl service calls) and mock I/O so a malicious or red-team payload can be kept in memory or have on-disk reads dynamically swapped; the write-up includes ARM64 patching details, sample hooking and mock implementations, caveats about code-signing/entitlements on Apple Silicon, and practical PoC notes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
