PlistDisguisedAsApple - Jamf Protect Evaluation Guide

Jamf Protect Evaluation Guide

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

The PlistDisguisedAsApple analytic detects the creation of suspicious LaunchDaemons or LaunchAgents that are masquerading as legitimate native-persistence items from Apple by using a conventional name and location.

LaunchDaemons and LaunchAgents are one of the most common forms of persistence on macOS, used by both legitimate software and malware alike to instruct macOS to automatically execute something at either system startup (Daemon) or at user login (Agent). Threat actors commonly include a persistence mechanism in an effort to maintain their foothold on the endpoint.

The typical naming convention for native macOS Launch items from Apple is com.apple.servicename.plist and macOS includes many native (and often third-party) Launch items across multiple locations to launch system services. Threat actors commonly use this to their advantage, naming and storing their Launch items in-line with these conventions in an effort to masquerade and hide them from discovery and removal, allowing their malware to be re-executed at next system startup. This masquerading technique was recently used by the malware families DazzleSpy and Sysjoker.

For more information about this type of threat see MITRE ATT&CK Tactic: Defense Evasion and ​MITRE ATT&CK Technique: Masquerading: Match Legitimate Name or Location.