Friday, April 11, 2025
HomeAppleNew Mac Malware OSX/Linker Bypasses Zero-day Flaw in macOS Gatekeeper Protection

New Mac Malware OSX/Linker Bypasses Zero-day Flaw in macOS Gatekeeper Protection

Published on

SIEM as a Service

Follow Us on Google News

A new Mac malware dubbed OSX/Linker leverages the recently disclosed macOS’ Gatekeeper vulnerability to get executed on victim’s machine without user permission or warnings.

The MacOS X GateKeeper zero-day vulnerability was publically disclosed by Filippo Cavallarin on May 24, as the Apple missed its 90 days deadline to fix the vulnerability.

The vulnerability resides in how the Gatekeeper treats the apps that loaded from a network share and the Internet. Gatekeeper, by default, considers the apps loaded from external drives and network shares as safe locations and allows to run without user consent.

- Advertisement - Google News

“As per-design, Gatekeeper considers both external drives and network shares as safe locations, and it allows any application they contain to run. By combining this design with two legitimate features of MacOS X, it will result in the complete deceivement of the intended behavior,” reads Filippo Cavallarin blog post.

Gatekeeper in apple is a mechanism to check for the presence of code signing certificates status and verifies the developer signature before allowing the application to execute.

OSX/Linker Malware

Intego’s malware research team noted few attempts of OSX/Linker to leverage the Zero-day flaw in macOS Gatekeeper by using a disk image file(.dmg) that used to distribute Mac software.

Anonymous users uploaded the samples to virustotal, Intego spotted four such samples, the first sample uploaded by an anonymous user from Israel, after that within seven minutes other three samples uploaded form United States.

OSX/Linker

Intego believes all the files uploaded by the same user, possibly he forgot to mask the IP address for at the time of uploading the first sample. The IP referenced by the disk images’ symlinks has been taken down by hosting company or voluntarily.

“It is not clear whether any of these specific disk images were ever part of an in-the-wild malware campaign. It is possible that these disk images, or subsequent disk images, may have been used in small-scale or targeted attacks, but so far this remains unknown.”

As usual, the threat actors behind the campaign disguised the disk images as Adobe Flash Player installers to trick the Mac users.

The developer ID associated with the samples has been reported by Intego to Apple and the Apple to revoke the developer ID associated.

Network administrators are recommended to lock down their network to prevent NFS communications from external IP, and for home users, there is no fix until Apple releases a security update.

IoC

108.168.175.167:111 or 875, or TCP port 2049

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity course online to keep yourself updated.

Memory Corruption Flaw in macOS Let Hackers run Malicious Code with Root Privileges

macOS Zero-Day Vulnerability Allows Hackers to Bypass Security Protections With Synthetic Clicks

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Threat Actors Leverage Email Bombing to Evade Security Tools and Conceal Malicious Activity

Threat actors are increasingly using email bombing to bypass security protocols and facilitate further...

Threat Actors Launch Active Attacks on Semiconductor Firms Using Zero-Day Exploits

Semiconductor companies, pivotal in the tech industry for their role in producing components integral...

Hackers Exploit Router Flaws in Ongoing Attacks on Enterprise Networks

Enterprises are facing heightened cyber threats as attackers increasingly target network infrastructure, particularly routers,...

Threat Actors Exploit Legitimate Crypto Packages to Deliver Malicious Code

Threat actors are using open-source software (OSS) repositories to install malicious code into trusted...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Threat Actors Leverage Email Bombing to Evade Security Tools and Conceal Malicious Activity

Threat actors are increasingly using email bombing to bypass security protocols and facilitate further...

Threat Actors Launch Active Attacks on Semiconductor Firms Using Zero-Day Exploits

Semiconductor companies, pivotal in the tech industry for their role in producing components integral...

Hackers Exploit Router Flaws in Ongoing Attacks on Enterprise Networks

Enterprises are facing heightened cyber threats as attackers increasingly target network infrastructure, particularly routers,...