<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Gatekeeper-Bypass on CuraSec</title><link>https://curasec.metacog.co.kr/tags/gatekeeper-bypass/</link><description>Recent content in Gatekeeper-Bypass on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 14 Jul 2026 12:08:08 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/gatekeeper-bypass/index.xml" rel="self" type="application/rss+xml"/><item><title>CrashStealer macOS Stealer Abuses Notarized Dropper to Evade Gatekeeper</title><link>https://curasec.metacog.co.kr/insights/2026-07-14-crashstealer-macos-malware-uses-notarized-dropper-to-pass-ga/</link><pubDate>Tue, 14 Jul 2026 12:08:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-14-crashstealer-macos-malware-uses-notarized-dropper-to-pass-ga/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> The native C++ implementation and Apple notarization abuse represent a more evasion-resistant stealer design than typical macOS threats; no CVE or patch exists, but engineers managing macOS endpoints should verify their EDR (Jamf, CrowdStrike Falcon for Mac, etc.) detects this family before active campaigns emerge.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> The notarized-dropper technique complicates Gatekeeper-based detection signals; SOC teams with macOS in scope should plan detections around post-notarization behavioral indicators (local password validation, C++ stealers) and check whether Jamf Threat Labs has published IOCs or YARA rules to incorporate this quarter.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>