Return of the mac(OS): Transparency, Consent, and Control (TCC) Database Manipulation

2024-04-11 Interpres Security

https://interpressecurity.com/resources/return-of-the-macos-tcc/

The macOS-focused analysis explains how adversaries can abuse Apple’s Transparency, Consent, and Control database, Full Disk Access, APFS snapshots, Finder permissions, and social engineering to weaken endpoint privacy protections. Its DPRK-relevant section links this defensive concern to Lazarus Group’s shift toward cross-platform operations and its targeting of cryptocurrency companies, developers, security researchers, and engineers. The report notes Operation Dream Job-style fake recruiting activity, including impersonation of technology-company recruiters, as a reason Lazarus targets are likely to include macOS-heavy technical workforces. For defenders tracking DPRK activity, the key value is the mapping of macOS privacy-control abuse paths to threat-hunting and prevention priorities rather than evidence of a single Lazarus intrusion using every described TCC bypass.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 317ce26cae14dc9a5e4d4667f00fee7… 2024-04-11 2024-04-11
HASH 37085f9c52e1dbe3edd3d33167eb921… 2024-04-11 2024-04-11
HASH b8cd150c5e4f6d6fff6e2dd43b8e955… 2024-04-11 2024-04-11
DOMAIN wojciechregula.blog 2024-04-11 2024-04-11
DOMAIN book.hacktricks.xyz 2024-04-11 2024-04-11
DOMAIN eclecticlight.co 2024-04-11 2024-04-11
HASH 6d3eff4e029db9d7b8dc076cfed5e23… 2023-07-12 2024-04-11
HASH 452c832a17436f61ad5f32ee1c97db0… 2023-06-21 2024-04-11
HASH b8a61adccefb13b7058e47edcd10a12… 2023-01-16 2024-04-11
DOMAIN blogs.blackberry.com 2021-02-28 2024-04-11

Related Actors

Related Reports

« Back