Back to projects

Selected project

macOS malware incident response.

A rushed developer-tool install turned into a defensive investigation of fake Apple-looking LaunchDaemons, hidden payload paths, root-owned processes, ad-hoc signed Mach-O binaries, and possible stealer or clipboard-hijacker indicators.

Role
Incident responder and evidence author
Stack
macOS, launchd, plutil, codesign
Contribution
Triage, static analysis, quarantine, verification
Outcome
Persistence removed and documented
01

Preserved evidence before cleanup

Suspicious LaunchDaemon files, hidden scripts, binary paths, code-signing output, hashes, and strings were documented before destructive cleanup actions were taken.

02

Confirmed persistence behavior

The strongest signal was not the Apple-like labels alone. It was those labels pointing to hidden payloads inside user-writable home-directory locations.

03

Kept analysis static

The payloads were not executed again. The investigation used plist parsing, shell-script review, process-path inspection, code-signing metadata, SHA-256 hashing, and strings extraction.

04

Verified persistence was gone

After quarantine, unloading, cleanup, process termination, and reboot, the fake LaunchDaemon labels did not reload and no root-owned payload process remained under the home directory.