Published February 23, 2026
| Version v1
Working paper
Open
Covert Cyber Warfare: Firmware-Persistent macOS Compromise and Steganographic Active Defense
Description
A sophisticated macOS attack achieved firmware-level persistence via NVRAM exploitation, surviving complete operating system reinstalls. Over a four-month campaign (June–October 2025), the compromise created 3,247 hidden directories, modified over 600,000 files, and exfiltrated data via APFS snapshots routed through the victim's own AWS account—rendering exfiltration indistinguishable from legitimate backup activity. The attack earns a CVSS score of 9.1 (Critical). In response, we present Chameleon—a dynamic steganographic defense framework that weaponizes steganography for active defense through three capabilities: canary injection for data-leak detection, covert channel identification, and counter-steganographic poisoning of attacker communication channels. The framework employs Shamir's Secret Sharing (3-of-5 threshold), Reed-Solomon error correction, and HKDF-based dynamic key rotation across five independent steganographic channels.
Files
covert-cyber-warfare.pdf
Files
(13.3 MB)
| Name | Size | Download all |
|---|---|---|
|
md5:a8545f962e060af4347f864afeedaa8c
|
93.1 kB | Preview Download |
|
md5:c97dbd9ae939da14a664d072b8d95309
|
13.2 MB | Preview Download |