BadXNU is the name of a conference presentation and rootkit-loading technique set focused on OS X/macOS kernel compromise rather than a documented in-the-wild malware family. The content describes methods for loading OS X kernel rootkits and bypassing Apple kernel extension protections on Mavericks and Yosemite. Reported capabilities include bypassing kext signing enforcement by patching the userland kextd daemon, obtaining kernel task access via vulnerabilities such as processor_set_tasks(), allocating and writing kernel memory with mach_vm_* APIs, abusing writable TrustedBSD MAC Framework policy structures (including mac_policy_list, mac_policy_conf, and mac_policy_ops) to redirect execution to a rootkit entry point, and using AppleHWAccess.kext for direct physical memory read/write to place a rootkit in memory and hijack an unused sysent entry for execution. The material also discusses handling KASLR via kas_info or leaks, fixing Mach-O relocations manually, and the impact of read-only kernel regions and CR0 write protection. The content associates BadXNU with presentations at SyScan, CodeBlue 2014, and BSides Lisbon 2015, and characterizes it as OS X rootkit research targeting Apple systems rather than attributing it to a specific threat actor or campaign. No high-confidence indicators of compromise are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware/rootkit referenced as the subject of a presentation titled 'BadXNU, A rotten apple!'.
An OS X kernel rootkit discussed in a BSides Lisbon 2015 presentation, focused on bypassing kext code-signing, abusing kernel vulnerabilities and OS X features, and leveraging TrustedBSD MAC Framework hooks or syscall table modification to gain kernel code execution and persistence.
OS X kernel rootkit discussed in the presentation, focused on bypassing kext code-signing restrictions, abusing kernel vulnerabilities and OS X features, and achieving kernel-level code execution/persistence via mechanisms such as TrustedBSD MACF hooks and syscall table modification.
BadXNU is presented as an OS X kernel rootkit/backdoor technique that bypasses kernel extension signing and leverages kernel vulnerabilities or OS X features to gain kernel code execution, install a TrustedBSD MAC policy hook, and execute persistent rootkit code in kernel memory.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.