macOS XCSSET Execution Indicators via bash-launched curl, osacompile, plutil, or zip

Flags macOS process chains involving bash-driven curl plus osacompile/plutil/zip operations targeting user and Group Containers paths.

FreeReviewedSigma · Medium · v2
Product
macos
Category
process_creation
Author
Tim Rauch (rule), Elastic (idea) (SigmaHQ), DRL 1.1
Published
2022-10-17
Updated
2026-07-31

What it detects

This rule identifies process execution patterns consistent with XCSSET malware activity on macOS, including bash-launched curl fetching specific script paths over HTTPS and build/modification steps using osacompile, plutil, and zip targeting Group Containers under /Users/. Such behavior matters because it reflects scripted payload retrieval and subsequent application tampering in the user environment. The detection relies on process creation telemetry capturing ParentImage, Image path suffixes, and CommandLine substrings.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.