A macOS persistence demonstration shows that an attacker with root privileges can modify the global /private/etc/man.conf configuration file and set MANPAGER to an attacker-controlled executable. The payload then runs whenever a user invokes the man command, turning the manual-page pager setting into an event-driven execution mechanism.
The proof of concept, tested on macOS Sonoma, compiled a benign C program named meow under /Users/Shared and recorded execution details in /tmp/meow.txt. The method requires privileged access and user interaction rather than providing login-time persistence; no public evidence currently attributes its use to a known malware family or APT group.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
A macOS Sonoma lab demonstration modified the root-protected global `/private/etc/man.conf` file to set `MANPAGER` to a benign `/Users/Shared/meow` executable. Invoking `man ls` then executed the payload, which logged proof-of-execution details to `/tmp/meow.txt`; the original configuration and test artifacts were subsequently restored or removed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcegithub.com
Open sourcecocomelonc.github.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.