Data exfiltration is the step in which data that should have stayed on a computer ends up somewhere else. MITRE ATT&CK, the public knowledge base of attacker behaviour maintained by MITRE, gives it its own tactic, TA0010, and defines it in one line: “The adversary is trying to steal data.” Everything that comes before, from a fake installer to a poisoned instruction given to an AI agent, matters to the victim mostly because of this moment. This article explains how exfiltration works on a Mac, which techniques MITRE catalogues, why it is hard to spot, and which network signals still give it away.
Collect, stage, send
Exfiltration is rarely a single action. MITRE describes a sequence. Data is first collected, for example from the Keychain, which, as ATT&CK technique T1555.001 notes, “stores account names, passwords, private keys, certificates, sensitive application data, payment data, and secure notes.” It is then often staged in a local folder (T1074.001) and compressed or encrypted (T1560); in MITRE’s words, “an adversary may compress and/or encrypt data that is collected prior to exfiltration,” which makes it smaller to send and harder to inspect on the way out. Only then is it sent. Each step happens on the Mac, but only the last one has to cross the network, which is why the network is where exfiltration is most consistently visible.
The techniques MITRE ATT&CK lists
The Exfiltration tactic currently contains nine techniques. They differ mainly in the channel used, and several have sub-techniques for specific destinations.
| ID | Technique | What it means in practice |
|---|---|---|
| T1041 | Exfiltration Over C2 Channel | Data leaves over the same connection the attacker already uses to send commands. |
| T1048 | Exfiltration Over Alternative Protocol | A different protocol or destination than the command channel, encrypted or not (T1048.001 to .003). |
| T1567 | Exfiltration Over Web Service | A legitimate service: code repository (.001), cloud storage (.002), text storage site (.003), webhook (.004). |
| T1029 | Scheduled Transfer | Sending at set times to blend in with normal activity. |
| T1030 | Data Transfer Size Limits | Sending in fixed-size chunks to stay under alert thresholds. |
| T1020 | Automated Exfiltration | Sending automatically as soon as data is collected; T1020.001 covers traffic duplication. |
| T1011 | Exfiltration Over Other Network Medium | A different medium than the main connection, such as Bluetooth (T1011.001). |
| T1052 | Exfiltration Over Physical Medium | Removable storage, such as a USB drive (T1052.001). |
| T1537 | Transfer Data to Cloud Account | Moving data to another account on the same cloud service. |
Infostealers: exfiltration as the whole purpose
On personal Macs, the most common programs built around exfiltration are infostealers: software that collects passwords, browser data and files and sends them to a server. MITRE’s entry for Cuckoo Stealer (S1153), a macOS program with the characteristics of spyware and an infostealer, reported by Kandji and SentinelOne in 2024, shows the pattern step by step. It collects Safari bookmarks, cookies and history (T1217), copies Keychain files (T1555.001), asks for the user’s password through spoofed system dialogs (T1056.002), takes screenshots with the built-in screencapture command (T1113), stages the results locally (T1074.001), and finally sends system information and captured passwords to its command server (T1041). MITRE lists the same exfiltration technique for other macOS families, including MacMa, XCSSET, ThiefQuest and LightSpy. Our article on Atomic Stealer follows another macOS stealer in more detail.
The final step is the only one that needs the internet, and it usually takes a few seconds. By the time anything else on the Mac looks unusual, the data has already gone, which is why detection has to watch outgoing connections rather than wait for visible symptoms.
Why it is hard to notice
MITRE’s description of Exfiltration Over Web Service (T1567) explains the difficulty well. Popular services give cover because “hosts within a network are already communicating with them prior to compromise,” “firewall rules may also already exist to permit traffic to these services,” and these providers “commonly use SSL/TLS encryption, giving adversaries an added level of protection.” An upload to a well-known cloud storage service over HTTPS looks, from the outside, like a backup. Scheduled transfers (T1029) and fixed-size chunks (T1030) go further and imitate the rhythm of ordinary traffic on purpose. A firewall that only filters incoming connections, as the one built into macOS does, plays no part here, since every exfiltration channel above starts on the Mac.
AI agents: a new path to the same outcome
AI agents on a Mac, such as coding assistants that read files, run commands and open connections, add a route that needs no installed stealer. The OWASP Gen AI Security Project defines indirect prompt injection as what happens when a model “accepts input from external sources, such as websites or files,” and gives an exfiltration scenario: a user asks a model to summarise a web page whose hidden instructions make it insert an image link to an outside address, so that loading the image carries the private conversation to that address. An agent that can also run curl or call a webhook turns the same trick into a file upload. In ATT&CK terms the outcome is still T1567 or T1048; only the starting point has changed, from an installer to a sentence the agent read. How FireAI recognises the agents themselves is covered in a separate article.
The signals that give it away
MITRE’s detection guidance for these techniques returns to the same network signs. For T1041 it points to processes that usually generate little traffic but suddenly send a large volume, and to encrypted connections “to rare external destinations or with abnormal byte ratios.” For T1567 it adds processes that “normally do not initiate network communications suddenly making outbound HTTPS connections with high outbound-to-inbound data ratios.” For T1030 and T1029 it suggests looking for uniform payload sizes at regular intervals and for LaunchAgent or launchd jobs that send to the same destination on a schedule. Translated to a single Mac, four questions cover most of it: is this app talking to a destination it has never used before; is it sending far more than it usually does; is it sending much more than it receives; and is it doing so on a clock?
Checking by hand with nettop
macOS includes nettop, which reports network use per process. With -P it shows one line per process, -L 1 prints a single sample in comma-separated form, and -J limits the columns. The counts are totals since each process started, so a single run tells you who has uploaded the most, not who is uploading right now; run it twice a minute apart and compare to see the change.
# bytes received and sent by each process, one sample
nettop -P -L 1 -J bytes_in,bytes_out
,bytes_in,bytes_out,
launchd.1,0,0,
syslogd.634,0,422,
apsd.640,5506,23880,
...A process whose sent bytes are far higher than its received bytes, and which you would not expect to upload anything, is worth a closer look. The limits are plain: nettop does not tell you where the data went, keeps no history, and will not alert you while you are not looking.
What FireAI flags
FireAI, the on-device firewall HisnLabs makes, measures two of those questions continuously and asks about a third. Every second, it adds up how much data the Mac sends to each country. A country is flagged as an upload spike when it received at least 5 MB in the last 10 seconds and at least ten times its usual amount: it moves to the top of the World map list in red with its upload speed, the menu bar icon shows an arrow and the country code, and the Home screen changes state. A spike stays flagged for a minute after it ends, and an upload that simply continues, such as a backup, becomes the new normal after a couple of minutes. FireAI does not block a spike on its own; it shows which apps and destinations are behind it so you can decide.
For AI agents, the Agent profile learns, over three days, where each of the 19 agents FireAI recognises normally connects. After that, a first-ever destination is flagged for review, as is an hour in which the agent uploaded at least four times its busiest hour so far and never less than 25 MB. In the Agent profile security mode, a new destination is blocked until you allow it. Outside agents, the connection prompt covers new destinations for every app: the first time an app tries to reach somewhere without a rule, FireAI pauses that connection and asks. All of this works on metadata only, host names and byte counts; FireAI does not read the contents of connections.
A short checklist
- Know which apps on your Mac are expected to upload, such as backup, sync and video-call apps, and treat uploads from others as questions.
- Watch for first-time destinations, especially for command-line tools and AI agents.
- Compare sent and received bytes per process; a high outbound-to-inbound ratio deserves a look.
- Review LaunchAgents and login items for jobs you do not recognise, since scheduled transfers need something to schedule them.
- Give AI agents only the folders and tokens they need, and keep their network destinations to a known list.
How FireAI and HisnLabs fit in
Exfiltration has to cross the network, and that is where FireAI watches: new destinations, uploads per country and per agent, on your Mac only. Try it free for 17 days.
FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its FireAI Pilot feature) on real traffic patterns, all without any of it leaving your Mac.
You can read the technical decisions behind it, or try FireAI for 17 days, at FireAI, by HisnLabs.
