4 ms·
Except for the part about moving a launch script into /Library/LaunchDaemons to achieve persistence.
by CodeWriter23 7y ago
Except for the part about moving a launch script into /Library/LaunchDaemons to achieve persistence.
- pvg 7y agoThat's the scaffolding, basically. A launch script in itself is not malicious and the idea is this would be less noticeable to automated or manual scans.
- moralestapia 7y ago>An executable file in itself is not malicious
- pvg 7y agoI'm not sure who you're quoting but it's not me. Easiest way to get a more detailed explanation is to read the linked technical analysis. The idea is to obfuscate and make detection harder by not-placing the actual final payload on the filesystem. Staging more-malicious things through things that look less-malicious is pretty much what makes malware mal.