CuraSec

tag: Gatekeeper-Bypass · 1 items

  • Engineer — Learn: The native C++ implementation and Apple notarization abuse represent a more evasion-resistant stealer design than typical macOS threats; no CVE or patch exists, but engineers managing macOS endpoints should verify their EDR (Jamf, CrowdStrike Falcon for Mac, etc.) detects this family before active campaigns emerge.
  • SOC/IR — Plan: The notarized-dropper technique complicates Gatekeeper-based detection signals; SOC teams with macOS in scope should plan detections around post-notarization behavioral indicators (local password validation, C++ stealers) and check whether Jamf Threat Labs has published IOCs or YARA rules to incorporate this quarter.
  • Leader — Skip