macOS File Persistence from Atomic MacOS Stealer (helper file and LaunchDaemon plist)

Flags macOS file creations used as persistence artifacts: per-user .helper files and a specific LaunchDaemon plist.

FreeReviewedSigma · High · v5
Product
macos
Category
file_event
Author
Jason Phang Vern - Onn, Robbin Ooi Zhen Heng (Gen Digital) (SigmaHQ), DRL 1.1
Published
2025-11-22
Updated
2026-07-31

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule looks for macOS persistence artifacts commonly used by Atomic MacOS Stealer variants: a user-level helper file created under /Users/<username> ending in .helper via a curl execution path, and a system LaunchDaemon plist at /Library/LaunchDaemons/com.finder.helper.plist. Persistence matters because it allows continued execution after initial compromise. The detection relies on file event telemetry that captures process filename endings and targeted file paths, including the LaunchDaemons plist creation.

Related detections9 linkedT1564.001 — drag to rearrange
Suspicious COOKIE SPIDER LaunchDaemon Persistence via com.finder.helper Property List (via file_event)
Suspicious Executable Written to User Documents Subfolder (via file_event)
Suspicious Sobolan Staging Directory Creation in var tmp (via file_event)
LaunchAgent or LaunchDaemon Persistence File Creation on macOS (via file_event)
FireWood Backdoor Persistence Files in Hidden kde-root Directory (via file_event)
Suspicious Attrib Hiding of Stealer Artifacts (via process_creation)
Malicious Mini Shai-Hulud gh-token-monitor Persistence Service (via file_event)
Suspicious perfctl Hidden IPC Directory Creation in tmp (via file_event)
Suspicious Executable Running From Fake Chrome User Profile Directory
macOS File Persistence from Atomic MacOS Stealer (helper file and LaunchDaemon plist)
Pivot detection · T1564.001 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.