Gatekeeper Quarantine Bypass
Files downloaded through a quarantine-aware app get the com.apple.quarantine attribute that triggers Gatekeeper's signature check; stripping it or avoiding it in the first place lets malware run unchecked.
When a quarantine-aware app (a browser, Mail, most download managers) writes a
file to disk, it tags it with the extended attribute com.apple.quarantine.
The first time that file is opened via Launch Services, Gatekeeper checks the
attribute, verifies the binary's code signature and notarization status, and
either allows it, warns the user, or blocks it outright depending on the
result. The check is triggered entirely by that one extended attribute —
remove it, or never let it get set in the first place, and the file launches
with no Gatekeeper check at all.
How it works
Removing the attribute from an already-downloaded file is a single command:
xattr -d com.apple.quarantine SuspiciousApp.appMore commonly, malware distributors simply choose a delivery path that never
sets the attribute to begin with: instructing the victim to extract an archive
with a tool that doesn't propagate quarantine metadata, or mounting a disk
image and running the app directly from the mounted volume rather than from a
location the download itself quarantined. A dropper stage can also apply an
ad-hoc signature (codesign -s -) to a payload it writes, which satisfies
Gatekeeper's baseline "is it signed at all" check on older policy
configurations even though ad-hoc signing carries no real trust.
Detection & analysis
Static analysis:
- On an acquired sample or a live system, check
xattr -p com.apple.quarantine <file>— its presence or absence, and the quarantine flags it encodes (which app set it, when), is directly informative: a user-facing executable with no quarantine attribute despite clearly having arrived over the network (email attachment, browser download folder) is a strong tell. - Verify actual notarization independent of a bare signature check:
spctl -a -vv <file>reports whether the binary is both signed and notarized, versus merely ad-hoc signed.
Dynamic analysis:
- Monitor
xattr/removexattrcalls (via EndpointSecurityES_EVENT_TYPE_AUTH_SETEXTATTR/ the corresponding delete event) targetingcom.apple.quarantineon files the same process or a related one just wrote. - Watch Launch Services events for an app launching directly from a mounted
disk image or an extracted-archive path rather than from
/Applications, which correlates with the quarantine-avoidance delivery pattern.
Detection rule hint:
Alert when com.apple.quarantine is explicitly removed from a file shortly
before that same file is executed, and separately flag executables launched
from mounted .dmg volumes or freshly-extracted archive paths that carry no
quarantine attribute at all despite the parent archive having been downloaded.