Malicious Bad Apples Remote Apple Events Lateral Movement via osascript

PremiumReviewedSigma · High · v1
Product
macos
Category
process_creation
Author
HuntRule
Published
2026-09-11
Updated
2026-09-11

ATT&CK techniques

Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects osascript invoking an eppc URL, matching the Bad Apples technique that weaponizes Remote Apple Events over TCP 3031 for lateral movement across macOS hosts. Sending AppleScript to a remote host via the eppc scheme lets an operator execute code on another Mac using native primitives. Such cross-host osascript activity is rarely benign and indicates hands-on movement.

Related detections9 linkedT1021.004 — drag to rearrange
Suspicious OpenSSH Reverse Tunnel Over HTTPS Port (Chaos Ransomware)
Suspicious Automated SSH Lateral Movement with Batch Mode (via process_creation)
OpenSSH Native Server Feature Installation (via powershell)
OpenSSH Server Listening on Socket (via openssh)
Suspicious macOS SSH Loopback Connection for TCC Bypass
Suspicious sshpass Noninteractive SSH Password Authentication (via process_creation)
Suspicious SimpleHelp Remote Access Client Spawning Discovery Commands (via process_creation)
OpenEDR ssh-shellhost Spawning Cmd or PowerShell With PTY on Windows
Bitbucket Audit: Global SSH Settings Changed
Malicious Bad Apples Remote Apple Events Lateral Movement via osascript
Pivot detection · T1021.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.