Return of the mac(OS): Transparency, Consent, and Control (TCC) Database Manipulation
2024-04-11 • Interpres Security •
https://interpressecurity.com/resources/return-of-the-macos-tcc/
The macOS-focused analysis explains how adversaries can abuse Apple’s Transparency, Consent, and Control database, Full Disk Access, APFS snapshots, Finder permissions, and social engineering to weaken endpoint privacy protections. Its DPRK-relevant section links this defensive concern to Lazarus Group’s shift toward cross-platform operations and its targeting of cryptocurrency companies, developers, security researchers, and engineers. The report notes Operation Dream Job-style fake recruiting activity, including impersonation of technology-company recruiters, as a reason Lazarus targets are likely to include macOS-heavy technical workforces. For defenders tracking DPRK activity, the key value is the mapping of macOS privacy-control abuse paths to threat-hunting and prevention priorities rather than evidence of a single Lazarus intrusion using every described TCC bypass.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 317ce26cae14dc9a5e4d4667f00fee7… | 2024-04-11 | 2024-04-11 |
| HASH | 37085f9c52e1dbe3edd3d33167eb921… | 2024-04-11 | 2024-04-11 |
| HASH | b8cd150c5e4f6d6fff6e2dd43b8e955… | 2024-04-11 | 2024-04-11 |
| DOMAIN | wojciechregula.blog | 2024-04-11 | 2024-04-11 |
| DOMAIN | book.hacktricks.xyz | 2024-04-11 | 2024-04-11 |
| DOMAIN | eclecticlight.co | 2024-04-11 | 2024-04-11 |
| HASH | 6d3eff4e029db9d7b8dc076cfed5e23… | 2023-07-12 | 2024-04-11 |
| HASH | 452c832a17436f61ad5f32ee1c97db0… | 2023-06-21 | 2024-04-11 |
| HASH | b8a61adccefb13b7058e47edcd10a12… | 2023-01-16 | 2024-04-11 |
| DOMAIN | blogs.blackberry.com | 2021-02-28 | 2024-04-11 |