Malicious Telegram Update LaunchDaemon Persistence on macOS

PremiumReviewedSigma · High · v1
Product
macos
Category
file_event
Author
HuntRule
Published
2026-09-27
Updated
2026-09-27

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects creation of a LaunchDaemon property list masquerading as a Telegram updater such as com.telegram2.update.agent.plist, a persistence mechanism used by BlueNoroff as analyzed by Huntress. Attackers install a LaunchDaemon with a trustworthy-sounding label to run their implant at boot. A LaunchDaemon impersonating a Telegram update service is a strong macOS persistence indicator.

Related detections9 linkedT1543.004 — drag to rearrange
Suspicious COOKIE SPIDER LaunchDaemon Persistence via com.finder.helper Property List (via file_event)
LaunchAgent or LaunchDaemon Persistence File Creation on macOS (via file_event)
Malicious Mini Shai-Hulud gh-token-monitor Persistence Service (via file_event)
Suspicious LaunchAgent or LaunchDaemon Load via launchctl
Malicious macOS LaunchDaemon Persistence Masquerading as Finder Helper
Suspicious LaunchDaemon Load via launchctl
Suspicious macOS LaunchAgent or LaunchDaemon Plist Creation
macOS File Persistence from Atomic MacOS Stealer (helper file and LaunchDaemon plist)
macOS launchctl Execution of Launch Agent/Daemon
Malicious Telegram Update LaunchDaemon Persistence on macOS
Pivot detection · T1543.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.