logo

Not Lost in Translation: Rosetta 2 Artifacts in macOS Intrusions

ID: ce923457-13c0-5dfe-9191-6d96d872bd7e

STIX ID: report--ce923457-13c0-5dfe-9191-6d96d872bd7e

Feed Name: Google Cloud Threat Intelligence

Threat Score
30/100

Date Published: 2025-03-03

Date Updated: 2026-04-27

Author: Mandiant

...
...

This report outlines how macOS Rosetta 2 Ahead-Of-Time (AOT) files can be leveraged for forensic analysis and the theoretical risk of AOT cache poisoning: investigators should compare generated known-good AOTs from x86-64 binaries against cached ARM64 AOTs to detect discrepancies or injected shellcode. It emphasizes that AOT artifacts, combined with FSEvents and Unified Logs, can provide residual evidence of intrusion—particularly when original binaries are deleted—and notes the behavior was observed on macOS versions between 13.5 and 14.7.2, while Mandiant has not seen AOT poisoning in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.