Not Lost in Translation: Rosetta 2 Artifacts in macOS Intrusions
ID: ce923457-13c0-5dfe-9191-6d96d872bd7e
STIX ID: report--ce923457-13c0-5dfe-9191-6d96d872bd7e
Feed Name: Google Cloud Threat Intelligence
This report outlines how macOS Rosetta 2 Ahead-Of-Time (AOT) files can be leveraged for forensic analysis and the theoretical risk of AOT cache poisoning: investigators should compare generated known-good AOTs from x86-64 binaries against cached ARM64 AOTs to detect discrepancies or injected shellcode. It emphasizes that AOT artifacts, combined with FSEvents and Unified Logs, can provide residual evidence of intrusion—particularly when original binaries are deleted—and notes the behavior was observed on macOS versions between 13.5 and 14.7.2, while Mandiant has not seen AOT poisoning in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
