MITRE ATT&CK technique

T1149

LC_MAIN Hijacking

**This technique has been deprecated and should no longer be used.** As of OS X 10.8, mach-O binaries introduced a new header called LC_MAIN that points to the binary’s entry point for execution. Previously, there were two headers to achieve this same effect: LC_THREAD and LC_UNIXTHREAD (Citation: Prolific OSX Malware History). The entry point for a binary can be hijacked so that initial execution flows to a malicious addition (either another section or a code cave) and then goes back to the initial entry point so that the victim doesn’t know anything was different (Citation: Methods of Mac Malware Persistence). By modifying a binary in this way, application whitelisting can be bypassed because the file name or application path is still the same.

TA0005

Linked Daily items

0 hits
No Daily items mapped yet.

Linked Incidents

0 hits
No incidents mapped yet.

Predicted CVE associations

0 items
No mappings yet for this technique.

These relationships come from the current triage artifact and are not official MITRE mappings.