← All Binaries

killall

killall is a built-in macOS utility that sends signals to processes selected by name. Although intended for legitimate process management, macOS malware has abused killall to terminate Terminal sessions, conceal malicious command execution, and repeatedly stop user-interface processes such as Finder, Dock, SystemUIServer, and NotificationCenter. This can disrupt normal desktop operation, suppress visible notifications, and force victims to continue an attacker-controlled interaction flow.

Author: Jason Phang Vern - Onn Created: 2026-07-26

Paths

/usr/bin/killall

Example Use Cases

Terminate Terminal to conceal malicious execution #

Terminate running Terminal processes after malicious commands have been launched, reducing visible evidence of execution and interfering with manual analysis.

killall Terminal

Repeatedly disrupt macOS user-interface processes #

Repeatedly terminate macOS user-interface processes at short intervals to disrupt normal desktop operation and force the victim to continue an attacker-controlled interaction flow.

while true; do killall Finder Dock SystemUIServer NotificationCenter 2>/dev/null; sleep 0.1; done

Suppress Notification Center #

Repeatedly terminate NotificationCenter to interfere with the display of macOS notifications.

killall NotificationCenter

Forcefully terminate a named process #

Send SIGKILL to immediately terminate processes that may ignore the default termination signal.

killall -9 Terminal

Detections

  • Process execution monitoring for killall
  • Detect repeated killall execution targeting macOS user-interface processes

Resources