MacOS Injection via Third Party Frameworks
ID: d19b437e-195f-5599-be40-9421aeedd115
STIX ID: report--d19b437e-195f-5599-be40-9421aeedd115
Feed Name: XPN Infosec Blog
This report demonstrates practical techniques for bypassing macOS process-injection and privacy protections by leveraging third‑party runtimes: abusing .NET Core’s debug transport (named pipes) to read/write memory and achieve code injection (including a PoC that writes shellcode and loads an Apfell implant), and using ELECTRON_RUN_AS_NODE to run signed/hardened Electron apps as Node to spawn processes that inherit app privacy permissions; the post includes full PoC code, implementation details, and evidence showing these methods work against hardened binaries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
