Skip to content

Gatekeeper Quarantine Bypass

Files downloaded through a quarantine-aware app get the com.apple.quarantine attribute that triggers Gatekeeper's signature check; stripping it or avoiding it in the first place lets malware run unchecked.

When a quarantine-aware app (a browser, Mail, most download managers) writes a file to disk, it tags it with the extended attribute com.apple.quarantine. The first time that file is opened via Launch Services, Gatekeeper checks the attribute, verifies the binary's code signature and notarization status, and either allows it, warns the user, or blocks it outright depending on the result. The check is triggered entirely by that one extended attribute — remove it, or never let it get set in the first place, and the file launches with no Gatekeeper check at all.

How it works

Removing the attribute from an already-downloaded file is a single command:

bash
xattr -d com.apple.quarantine SuspiciousApp.app

More commonly, malware distributors simply choose a delivery path that never sets the attribute to begin with: instructing the victim to extract an archive with a tool that doesn't propagate quarantine metadata, or mounting a disk image and running the app directly from the mounted volume rather than from a location the download itself quarantined. A dropper stage can also apply an ad-hoc signature (codesign -s -) to a payload it writes, which satisfies Gatekeeper's baseline "is it signed at all" check on older policy configurations even though ad-hoc signing carries no real trust.

Detection & analysis

Static analysis:

  • On an acquired sample or a live system, check xattr -p com.apple.quarantine <file> — its presence or absence, and the quarantine flags it encodes (which app set it, when), is directly informative: a user-facing executable with no quarantine attribute despite clearly having arrived over the network (email attachment, browser download folder) is a strong tell.
  • Verify actual notarization independent of a bare signature check: spctl -a -vv <file> reports whether the binary is both signed and notarized, versus merely ad-hoc signed.

Dynamic analysis:

  • Monitor xattr/removexattr calls (via EndpointSecurity ES_EVENT_TYPE_AUTH_SETEXTATTR/ the corresponding delete event) targeting com.apple.quarantine on files the same process or a related one just wrote.
  • Watch Launch Services events for an app launching directly from a mounted disk image or an extracted-archive path rather than from /Applications, which correlates with the quarantine-avoidance delivery pattern.

Detection rule hint:

Alert when com.apple.quarantine is explicitly removed from a file shortly before that same file is executed, and separately flag executables launched from mounted .dmg volumes or freshly-extracted archive paths that carry no quarantine attribute at all despite the parent archive having been downloaded.

Votes

Comments(0)