Lateral Movement on macOS: Unique and Popular Techniques and In-the-Wild Examples
ID: cc1dc4f6-d14e-5946-b6e0-991d50d905d3
STIX ID: report--cc1dc4f6-d14e-5946-b6e0-991d50d905d3
Feed Name: Palo Alto Networks Unit 42
This report examines macOS lateral movement techniques—SSH key theft and persistence via authorized_keys, misuse of Apple Remote Desktop (ARD), and Remote Apple Events (RAE)—with real-world examples (ZuRu, PyTorch dependency confusion, SSH‑Snake, Insekt) and actionable detection guidance. It highlights how attackers enable and leverage ARD (kickstart, ardagent, screensharingd over ports like 3283) and RAE (eppc over port 3031) to execute commands, exfiltrate data, and maintain persistence, and it recommends monitoring key file changes, suspicious process trees, relevant Unified Log predicates, and network activity to detect and disrupt these techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
