1
Return

Characterizing Tactics, Techniques, and Procedures in the macOS Threat Landscape

delete2025-12-14
delete0
delete
OA
AI
D
Daniel Lastanao Miró
J
Javier Carrillo-Mondéjar
R
Ricardo J. Rodríguez
DOI:10.1016/j.cose.2025.104806delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
As macOS systems increasingly become malware targets, understanding the tactics, techniques, and procedures (TTPs) used by adversaries is essential to improving defense strategies. This paper provides a systematic and detailed analysis of macOS malware using the MITRE ATT&CK framework, focusing on TTPs at key stages of the malware attack cycle. Leveraging a comprehensive dataset of 57,636 macOS malware samples collected between November 2006 and October 2024, we employ both static and dynamic analysis techniques to uncover patterns in adversary behavior. Our analysis, primarily based on static analysis techniques, offers a broad representation of macOS malware and highlights common characteristics across samples. While we only partially explore dynamic behaviors, we identify recurring patterns that align with specific TTPs in the MITRE ATT&CK framework, such as persistence and defense evasion. This mapping contributes to a more structured understanding of macOS threats and can help inform future detection and mitigation efforts.
Keywords:
macOS malware
MITRE ATT&CK framework
Malware behavior
Static and dynamic analysis
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

C
Computers and Security
IF:
5.4
Papers:
4.6K
Citations:
1.4W

Organization

U
Universidad de Zaragoza
Scholars:
380
Papers: 162
Citations: 1.3W
Cited Papers

Cited Papers

Citing Papers

Citing Papers