Suspicious Keylogger Capture Database Written to macOS Temp Directory

PremiumReviewedSigma · Medium · v1
Product
macos
Category
file_event
Author
HuntRule
Published
2026-09-27
Updated
2026-09-27

ATT&CK techniques

Cred Access → Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects creation of google_cache.db under a macOS temp directory such as private tmp, the collection store used by the BlueNoroff keylogger and screen capture module analyzed by Huntress. The implant records keystrokes and screenshots into this disguised database before exfiltration. A capture database with a browser-cache-like name in a temp path is a strong collection indicator.

Related detections9 linkedT1056.001 — drag to rearrange
Suspicious Keylog and Screenshot Files in windows-cache Directory (OtterCookie)
Suspicious Screen and Audio Capture via Problem Steps Recorder
Malicious Kong RAT Keylogger Capture File Creation
Malicious BRUSHLOGGER Rundll32 Execution from ProgramData (via process_creation)
Suspicious REMCOS Screenshot Capture File via file_event
Suspicious WezRat Keylog File in Temp Directory
Suspicious Larva-24009 Keylogger Log Staging in OneDrive Path (via file_event)
Suspicious RDP Shadow Session Started - Native (via rdp)
Suspicious Kimsuky AlphaSeed Artifacts in edge Hidden Directory (via file_event)
Suspicious Keylogger Capture Database Written to macOS Temp Directory
Pivot detection · T1056.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.