Back to Intel

Intel Node

Bad Apples: Weaponizing native macOS primitives for movement and execution

criticaltradecraft2026-04-21T10:00:29+00:00source excerpt
tradecraftwindowslinuxcloud

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

Cisco Talos documents several macOS living-off-the-land (LOTL) techniques, demonstrating that native pathways for movement and execution remain accessible to those who understand the underlying architecture.

As macOS adoption grows among developers and DevOps, it has become a high value target; however, native "living-off-the-land" (LOTL) techniques for the platform remain significantly under-documented compared to Windows.   Adversaries can bypass security controls by repurposing native features like Remote Application Scripting (RAS) for remote execution and abusing Spotlight metadata (Finder comments) to stage payloads in a way that evades static file analysis.

  Attackers can move toolkits and establish persistence using built-in protocols such as SMB, Netcat, Git, TFTP, and SNMP operating entirely outside the visibility of standard SSH-based telemetry.

Read Original Source