BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Dylib Hijacking on macOS: Dead or Alive?\n   Tags: D
 EF CON Official Talk | Demo 💻\n   When: Saturday\, Aug 8\, 13:00 - 13:5
 9 PDT\n   Where: LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3 - [1]M
 ap\n\n   Description:\n\n   Over a decade ago\, a much younger Patrick sho
 wed that macOS (then OS\n   X) was vulnerable to what had long been consid
 ered a Windows-only\n   attack: dynamic library hijacking. By planting mal
 icious libraries in\n   the right place\, attackers could achieve stealthy
  persistence\, inject\n   code into trusted processes\, and even bypass co
 re Apple security\n   mechanisms.\n\n   Today\, an older (and hopefully wi
 ser) Patrick revisits that work to\n   answer a simple question: is dylib 
 hijacking truly dead on modern\n   macOS\, or has Apple’s decade of defe
 nses\, including Gatekeeper\, App\n   Translocation\, Notarization\, and t
 he Hardened Runtime\, simply made it\n   harder?\n\n   This talk revisits 
 the technique in 2026\, analyzing these mitigations\n   and evaluating the
 ir real-world effectiveness. While the attack\n   surface has been signifi
 cantly reduced\, we show dylib hijacking\n   remains possible under the ri
 ght conditions. Through real-world\n   examples and live demos\, we explor
 e how modern applications can still\n   be coerced into loading attacker-c
 ontrolled libraries\, enabling code\n   execution within trusted processes
  and bypassing controls such as TCC.\n\n   Finally\, we present practical 
 detection and defense strategies\,\n   including novel approaches leveragi
 ng Endpoint Security to detect (and\n   block!) malicious library loads at
  runtime.\n\n   "Dylib hijacking on OS X"\n    www.virusbulletin.com/vir
 usbulletin/2015/03/dylib-hijacking-os-x\n\n   "Tweaking macOS security con
 trols to thwart application bundle\n   manipulation"\n    redcanary.com/
 blog/threat-detection/mac-application-bundles/\n\n   "What's New in Securi
 ty" (WWDC 2016) \n   devstreaming-cdn.apple.com/videos/wwdc/2016/706sgjv
 zkvg6rrg9icw/706/706_whats_new_in_security.pdf\n\n   SpeakerBio:  Patrick 
 Wardle\, CEO and Co-Founder at DoubleYou\n\n   Patrick Wardle is the cofou
 nder of the Objective-See Foundation\, CEO\n   and cofounder of DoubleYou\
 , and author of The Art of Mac Malware\n   series. He previously worked at
  NASA and the NSA\, and has presented at\n   countless security conference
 s\, making him intimately familiar with\n   aliens\, spies\, and talking n
 erdy.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260808T205900Z
DTSTART:20260808T200000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3
SUMMARY:Dylib Hijacking on macOS: Dead or Alive?
END:VEVENT
END:VCALENDAR
