Trusted Design

T1144 - Gatekeeper Bypass

概要

In macOS and OS X, when applications or programs are downloaded from the internet, there is a special attribute set on the file called com.apple.quarantine. This attribute is read by Apple's Gatekeeper defense program at execution time and provides a prompt to the user to allow or deny execution.

Apps loaded onto the system from USB flash drive, optical disk, external hard drive, or even from a drive shared over the local network won’t set this flag. Additionally, other utilities or events like drive-by downloads don’t necessarily set it either. This completely bypasses the built-in Gatekeeper check. (Citation: Methods of Mac Malware Persistence) The presence of the quarantine flag can be checked by the xattr command xattr /path/to/MyApp.app for com.apple.quarantine. Similarly, given sudo access or elevated permission, this attribute can be removed with xattr as well, sudo xattr -r -d com.apple.quarantine /path/to/MyApp.app. (Citation: Clearing quarantine attribute) (Citation: OceanLotus for OS X)

In typical operation, a file will be downloaded from the internet and given a quarantine flag before being saved to disk. When the user tries to open the file or application, macOS’s gatekeeper will step in and check for the presence of this flag. If it exists, then macOS will then prompt the user to confirmation that they want to run the program and will even provide the URL where the application came from. However, this is all based on the file being downloaded from a quarantine-savvy application. (Citation: Bypassing Gatekeeper)

管理者によるコメント

MITRE ATT&CKにおいて、T1144は「Gatekeeper Bypass(Gatekeeperのバイパス)」として定義されている「防御回避(Defense Evasion)」のテクニックです。

macOSの標準セキュリティ機能である「Gatekeeper(ゲートキーパー)」の検証メカニズム(拡張属性 com.apple.quarantine やコード署名検証)を破り、Web経由でダウンロードした未承認・未署名の悪意あるアプリケーションやスクリプトを警告なしで実行させる手法です。

1. 概要(攻撃者は何を実現できるのか?)

この手法で攻撃者は、「macOSユーザーが外部から取得したプログラムを実行しようとした際に発生するブロック画面(ダイアログ)を無効化し、マルウェアをそのまま起動させること」を実現します。

2. 攻撃の流れ

Gatekeeperのバイパスには、属性の手動削除、Gatekeeperの設計上の不備(パス・トラバーサルやシンボリックリンク)の悪用、またはコマンドでの機能無効化など複数のアプローチが存在します。

  1. 初期侵入と悪意あるファイルの配置:
    フィッシングサイト等からマルウェア(例: DMGファイルやZipアーカイブ)をダウンロードさせます。

  2. Quarantine(検疫)属性の削除またはバイパス(T1144の発動):
    攻撃者は端末上で以下のような操作を実行します。

    • xattr コマンドによる検疫属性の抹消:
      xattr -d com.apple.quarantine /path/to/malicious.app

    com.apple.quarantine 属性を消去することで、macOSに「このファイルはインターネットからダウンロードされたものではない(ローカルで作成された安全なファイル)」と錯覚させます。

    • Gatekeeper自体の一時的・恒久的無効化(管理者権限が必要):
      spctl --master-disable

    spctl(Security Assessment Policy subsystem)のセキュリティポリシースキャンを完全無効化(「すべての元からのアプリケーションを許可」状態)にします。

    • 圧縮形式やパス構造の不備の悪用:
      Gatekeeperが再帰的に検疫属性を付与しない特定の構造(例: 内部にシンボリックリンクを含む特定のZip/Tar構造)を突いて、警告を発生させずに展開・実行させます。
  3. 悪意あるコードの正常実行:
    Gatekeeperによる検証をパスしたマルウェアが警告なしでそのまま起動し、バックドアの設置や情報窃取を開始します。

3. 防御・対策

macOSの設定管理と、検疫属性の変更や spctl コマンドの監視が必要です。

4. 重要ポイント

5. 関連する主なCWE

6. 関連する代表的なCVE

Gatekeeperには過去に複数の重大なバイパス脆弱性(CVE)が発見されており、パッチ適用前のゼロデイ攻撃で頻繁に悪用されました。

実務上のアドバイス:
Mac端末を管理する情シス・SOCにおいて、ログ内に xattr -d com.apple.quarantine や spctl --master-disable が記録された場合、またはユーザーの Downloads フォルダ配下で作成されたアプリから検疫属性が不自然に消失している場合は、高確率で macOS 向けマルウェアの初期感染処理(旧 T1144 / 現 T1553.001)が動作しています。

該当Mac端末の隔離、spctl --status によるGatekeeper状態の再有効化確認、および直近でダウンロードされた不審なファイル(.dmg, .pkg, .zip)の特定を急いでください。

分析

この攻撃手法を利用する脅威アクター

関連する CVE

この攻撃手法に関連する CVE は登録されていません。

攻撃手法 – 脅威アクター Graph


← Technique一覧に戻る ← Tactics一覧に戻る