MacOS Native Tools Enable Stealthy Enterprise Attacks
ID: 26957749-61a7-52a2-98da-df2502edb333
STIX ID: report--26957749-61a7-52a2-98da-df2502edb333
Feed Name: Infosecurity Magazine (News)
Cisco Talos research describes how attackers are repurposing native macOS features — including Remote Application Scripting (RAS), AppleScript, Finder comments stored in Spotlight metadata, and legitimate protocols/tools like SMB, netcat, git, TFTP and SNMP — to execute code, move laterally and evade detection; the report highlights limited visibility for traditional endpoint/network controls and recommends process-lineage analysis, metadata monitoring and stricter MDM and inter-application communication controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
