In macOS and OS X, when applications or programs are downloaded from the internet, there is a special attribute set on the file called com.apple.quarantine. This attribute is read by Apple's Gatekeeper defense program at execution time and provides a prompt to the user to allow or deny execution.
Apps loaded onto the system from USB flash drive, optical disk, external hard drive, or even from a drive shared over the local network won’t set this flag. Additionally, other utilities or events like drive-by downloads don’t necessarily set it either. This completely bypasses the built-in Gatekeeper check. (Citation: Methods of Mac Malware Persistence) The presence of the quarantine flag can be checked by the xattr command xattr /path/to/MyApp.app for com.apple.quarantine. Similarly, given sudo access or elevated permission, this attribute can be removed with xattr as well, sudo xattr -r -d com.apple.quarantine /path/to/MyApp.app. (Citation: Clearing quarantine attribute) (Citation: OceanLotus for OS X)
In typical operation, a file will be downloaded from the internet and given a quarantine flag before being saved to disk. When the user tries to open the file or application, macOS’s gatekeeper will step in and check for the presence of this flag. If it exists, then macOS will then prompt the user to confirmation that they want to run the program and will even provide the URL where the application came from. However, this is all based on the file being downloaded from a quarantine-savvy application. (Citation: Bypassing Gatekeeper)
MITRE ATT&CKにおいて、T1144は「Gatekeeper Bypass(Gatekeeperのバイパス)」として定義されている「防御回避(Defense Evasion)」のテクニックです。
macOSの標準セキュリティ機能である「Gatekeeper(ゲートキーパー)」の検証メカニズム(拡張属性 com.apple.quarantine やコード署名検証)を破り、Web経由でダウンロードした未承認・未署名の悪意あるアプリケーションやスクリプトを警告なしで実行させる手法です。
この手法で攻撃者は、「macOSユーザーが外部から取得したプログラムを実行しようとした際に発生するブロック画面(ダイアログ)を無効化し、マルウェアをそのまま起動させること」を実現します。
「開発元を検証できないため開けません」警告の無力化:
通常、インターネットからダウンロードされたアプリには quarantine(検疫)属性が付与され、Gatekeeperがコード署名や公認(Notarization)を検証してブロックします。本手法はこの保護をすり抜けます。
マルウェア実行の「最初のハードル」の突破:
macOSにおける初期侵入(Drive-by Downloadやフィッシング)において、ユーザーの確認ダイアログ介入による検出・拒否を回避するために利用されます。
Gatekeeperのバイパスには、属性の手動削除、Gatekeeperの設計上の不備(パス・トラバーサルやシンボリックリンク)の悪用、またはコマンドでの機能無効化など複数のアプローチが存在します。
初期侵入と悪意あるファイルの配置:
フィッシングサイト等からマルウェア(例: DMGファイルやZipアーカイブ)をダウンロードさせます。
Quarantine(検疫)属性の削除またはバイパス(T1144の発動):
攻撃者は端末上で以下のような操作を実行します。
xattr コマンドによる検疫属性の抹消:xattr -d com.apple.quarantine /path/to/malicious.appcom.apple.quarantine 属性を消去することで、macOSに「このファイルはインターネットからダウンロードされたものではない(ローカルで作成された安全なファイル)」と錯覚させます。
spctl --master-disablespctl(Security Assessment Policy subsystem)のセキュリティポリシースキャンを完全無効化(「すべての元からのアプリケーションを許可」状態)にします。
悪意あるコードの正常実行:
Gatekeeperによる検証をパスしたマルウェアが警告なしでそのまま起動し、バックドアの設置や情報窃取を開始します。
macOSの設定管理と、検疫属性の変更や spctl コマンドの監視が必要です。
spctl および xattr コマンド実行の監視(最重要):
macOS向けのEDRや監査ログ(Auditd, Endpoint Security Framework)を用いて、xattr -d com.apple.quarantine や spctl --master-disable などのコマンド実行(プロセス生成イベント)を監視・自動通知します。
MDM(モバイルデバイス管理)によるGatekeeperの強制有効化:
Jamf Pro や Kandji などのMDMを用いて、Gatekeeperを常に有効(spctl --master-enable)に保ち、ユーザーやプロセスによる無効化設定をGPO風に上書き・ブロックします。
App Storeおよび確認済みの開発元からのアプリのみ許可:
「システム設定」>「プライバシーとセキュリティ」にて、アプリケーションの実行許可範囲を最厳格に設定し、構成プロファイルで変更をロックします。
macOS特有のシールドに対する基本バイパス:
Windowsにおける SmartScreen / AppLocker バイパスに相当する、macOS攻撃インフラにおける最重要テクニックの一つです。
ソーシャルエンジニアリング型インストーラーでの多用:
偽のAdobe Flash Player更新プログラムや各種クラックソフトに見せかけたmacOSマルウェアのスクリプト内に、ほぼ確実に xattr -d com.apple.quarantine の処理が埋め込まれています。
CWE-295: Improper Certificate Validation(不適切な証明書検証)
コード署名や公認(Notarization)の検証ロジックをすり抜けて、未署名または不正な署名を持つアプリケーションの実行を許してしまう脆弱性。
CWE-693: Protection Mechanism Failure(保護メカニズムの動作不全)
OSが提供する標準の防御機能(Gatekeeper)が、特定の属性操作やコマンド実行によって容易に無効化・バイパスされてしまう構造上の問題。
Gatekeeperには過去に複数の重大なバイパス脆弱性(CVE)が発見されており、パッチ適用前のゼロデイ攻撃で頻繁に悪用されました。
CVE-2021-30657(Gatekeeper Bypassの脆弱性):
Shlayerマルウェアが直面・悪用した脆弱性。SysEx(Scripting Definition)形式のスクリプトアプリを特定構造で作成することで、Gatekeeperがコード署名チェックを完全にスキップして実行してしまう非解釈型の欠陥でした。
CVE-2022-42821(Achilles脆弱性):
ACL(アクセス制御リスト)属性を巧みに構成したZipファイルを展開した際、Safariが com.apple.quarantine 属性を付与できなくなる脆弱性。Gatekeeperの制限を一切受けずに未署名アプリを実行できる状態を作り出しました。
実務上のアドバイス:
Mac端末を管理する情シス・SOCにおいて、ログ内に xattr -d com.apple.quarantine や spctl --master-disable が記録された場合、またはユーザーの Downloads フォルダ配下で作成されたアプリから検疫属性が不自然に消失している場合は、高確率で macOS 向けマルウェアの初期感染処理(旧 T1144 / 現 T1553.001)が動作しています。
該当Mac端末の隔離、spctl --status によるGatekeeper状態の再有効化確認、および直近でダウンロードされた不審なファイル(.dmg, .pkg, .zip)の特定を急いでください。
この攻撃手法に関連する CVE は登録されていません。