Apple unwittingly authorized this common Mac malware null


Apple’s much-celebrated security system has been found to have mistakenly authorized a Mac malware campaign, allowing it to run free on macOS devices.
Since February, Apple has required all applications running on macOS (including apps sourced from outside the official Mac App Store) to be fully vetted before a user can run the executable file.
However, a Shlayer adware campaign managed to circumvent these tightened security filters, despite remaining largely identical to previous known strains.
Mac malware
Apple has long enjoyed a reputation as manufacturer of the most secure devices around, which have been described as immune to the various cyberthreats facing Windows OS.
However, while it is technically true that malware designed to target Windows devices cannot run on macOS, Apple devices can still be vulnerable to similar threat types.
In this instance, attackers targeted macOS devices with Shlayer adware, designed to intercept browser queries and feed its own ads into search results, generating significant sums in revenue for its operators.
The Mac malware was previously found to be distributed by over 1,000 websites, each of which disguised the download in a slightly different fashion. At its peak, Shlayer was reportedly present on 10% of all Mac computers.
This latest malware campaign was discovered by college student Peter Dantini, who happened across a Shlayer download hosted on a fake Adobe Flash landing page. He was surprised to learn that macOS did not intervene when he deliberately attempted to activate the download, as it is designed to do.
Dantini passed his discovery over to security researcher Patrick Wardle – who recently identified a bug sequence that could be used to hijack Mac devices – to investigate further and liaise with Apple.
“I had been expecting that if someone were to abuse the notarization system it would be something more sophisticated or complex,” said Wardle.
“But in a way I’m not surprised that it was adware that did it first. Adware developers are very innovative and constantly evolving, because they stand to lose a ton of money if they can’t get around new defenses.”
Apple was notified of the issue on August 28 and claims to have withdrawn the malware’s notarization certificate on the same day.
“Malicious software constantly changes, and Apple’s notarization system helps us keep malware off the Mac and allow us to respond quickly when it’s discovered,” said the firm.
“Upon learning of this adware, we revoked the identified variant, disabled the developer account and revoked the associated certificates. We thank the researchers for their assistance in keeping our users safe.”
However, Wardle found that Shlayer was still alive and kicking two days later, notarized using a different Apple Developer ID. It is currently unclear how Shlayer continues to deceive the application vetting process.
Via WIRED
Apple’s much-celebrated security system has been found to have mistakenly authorized a Mac malware campaign, allowing it to run free on macOS devices. Since February, Apple has required all applications running on macOS (including apps sourced from outside the official Mac App Store) to be fully vetted before a user…
Recent Posts
- The Xbox Wireless Controller is just $39 right now
- This external Geforce RTX 4090M GPU is the most powerful you can buy right now and creatives will absolutely love it
- Kick off Pokémon Day 2025 with this gorgeous short film
- BitTorrent for LLM? Exo software is a distributed LLM solution that can run even on old smartphones and computers
- The dream of PictoChat on the Nintendo DS lives on in this iMessage app
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010