{"id":62258,"date":"2025-12-28T17:42:35","date_gmt":"2025-12-28T16:42:35","guid":{"rendered":"https:\/\/www.apfelpatient.de\/?p=62258"},"modified":"2025-12-29T14:32:44","modified_gmt":"2025-12-29T13:32:44","slug":"macos-gatekeeper-bypassed-through-a-two-stage-malware-chain","status":"publish","type":"post","link":"https:\/\/www.apfelpatient.de\/en\/news\/macos-gatekeeper-durch-zweistufige-malware-kette-umgangen","title":{"rendered":"macOS Gatekeeper bypassed via two-stage malware chain"},"content":{"rendered":"<p class=\"has-drop-cap\"><strong>Security features like Gatekeeper are among macOS&#039;s most important protection mechanisms. They are designed to prevent malware from running undetected and sensitive data from being leaked. However, a recent report shows that attackers have once again found ways to circumvent these safeguards. A new variant of the MacSync Stealer specifically exploits Apple&#039;s notarization process, thus achieving a new level of sophistication in attacks on macOS.<\/strong><\/p>\n\n\n\n<p>Gatekeeper has been considered an effective first line of defense against malware on macOS for years. In the past, attackers usually needed to trick users into taking action to circumvent this protection. This is precisely where the new attack method comes in. It reduces the necessary steps to a minimum and makes the infection process significantly less noticeable.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-gatekeeper-und-seine-bisherige-rolle-unter-macos\">Gatekeeper and its previous role under macOS<\/h4>\n\n\n\n<p>Gatekeeper on macOS checks whether applications are signed and notarized by Apple. If this is not the case, execution is blocked or at least accompanied by clear warnings. Previous malware campaigns therefore attempted to trick users into deliberately bypassing these warnings. Typical methods included manually opening applications via the context menu or running scripts via the Terminal.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-neue-erkenntnisse-von-jamf-threat-labs\">New findings from Jamf Threat Labs<\/h4>\n\n\n\n<p class=\"translation-block\">Researchers at Jamf Threat Labs <a href=\"https:\/\/www.jamf.com\/blog\/macsync-stealer-evolution-code-signed-swift-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\" data-wpel-link=\"external\">have reported<\/a> on a new variant of the MacSync Stealer that takes a different approach. Instead of bypassing Gatekeeper, it abuses its trust. The malware is distributed via a code-signed and notarized Swift application. This means the app formally meets all the requirements to be launched on macOS without a warning message.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-tarnung-als-legitime-anwendung\">Camouflage as a legitimate application<\/h4>\n\n\n\n<p>The new variant is being distributed as an installer for a purported application called &quot;zk-Call &amp; Messenger.&quot; Users download this app via a web browser and can then open it normally with a double-click. Unlike previous versions, no right-click or explicit confirmation of opening is necessary, as it is a signed executable file.<\/p>\n\n\n\n<p>An inspection of the installation file shows that it is correctly signed and notarized. It is also linked to a valid developer team ID. The file size of approximately 25.5 MB is noteworthy. The actual script is relatively small, but the application has been bloated with additional files such as PDFs. This makes it appear to be a legitimate installer simply due to its size.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-zweistufiger-aufbau-der-malware\">The malware has a two-stage structure<\/h4>\n\n\n\n<p>The installation app does not directly contain the MacSync Stealer. After launching, it downloads a second payload from an external server. This server contains the actual malware, which is then installed on the target system. Technically, it is still an encrypted dropper. Many of the typical characteristics of MacSync Stealer are present.<\/p>\n\n\n\n<p>The crucial difference lies in the first stage. By using a notarized and signed app, this stage can completely bypass Gatekeeper&#039;s protection mechanisms. The actual malware is only downloaded from the internet later.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-einordnung-und-bisherige-entwicklungen\">Classification and previous developments<\/h4>\n\n\n\n<p>Jamf describes this case as an example of how malware authors are strategically refining their distribution methods to achieve as many infections as possible. According to the researchers, such a combination of a Swift-based, code-signed, and notarized application with a post-loaded payload has not been observed before.<\/p>\n\n\n\n<p>The trend of embedding malware in seemingly legitimate executable files is not new. Back in 2020, it was revealed that malicious code had been able to bypass Apple&#039;s notarization process because harmful scripts within applications went undetected. What&#039;s new this time is that the notarized app itself doesn&#039;t contain any malicious code, but only retrieves it from the internet after passing all the necessary checks. This significantly complicates detection during the notarization process.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-reaktion-und-aktuelle-situation\">Reaction and current situation<\/h4>\n\n\n\n<p>Jamf reported the associated developer team ID to Apple. The affected certificate was subsequently revoked. However, at the time of publication of this report, the code directory hashes were not yet included in Apple&#039;s revocation list. This demonstrates that a window of time can still exist between discovery and complete revocation.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-macos-sicherheit-endet-nicht-bei-gatekeeper\">macOS security doesn&#039;t end with Gatekeeper<\/h3>\n\n\n\n<p>The MacSync Stealer case illustrates that despite Gatekeeper and notarization, macOS is not a completely closed system. Attackers deliberately exploit the trust built through signing and authentication. Therefore, meticulous digital hygiene remains crucial for Mac users. This includes carefully checking which software is installed and from which sources it originates, such as from well-known developer websites or directly from the Mac App Store. Gatekeeper is an important security mechanism in macOS, but it does not replace vigilance and critical behavior in everyday use. (Image: Shutterstock \/ Pungu x)<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.apfelpatient.de\/en\/news\/apple-intelligence-must-pass-chinas-ai-censorship-test\">Apple Intelligence must pass China&#039;s AI censorship test<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.apfelpatient.de\/en\/news\/ted-lasso-season-4-producers-announce-possible-start-date\">Ted Lasso Season 4: Producers announce possible release date<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.apfelpatient.de\/en\/news\/apple-allows-alternative-app-stores-on-ios-in-brazil\">Apple allows alternative app stores on iOS in Brazil<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.apfelpatient.de\/en\/news\/ios-26-3-receives-praise-from-the-eu-for-new-features\">iOS 26.3 receives praise from the EU for new features<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.apfelpatient.de\/en\/news\/whatsapp-is-testing-a-new-quiz-feature-for-channels\">WhatsApp is testing a new quiz feature for channels<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.apfelpatient.de\/en\/news\/apple-and-china-meet-at-government-level-confirmed\">Apple and China: Government-level meeting confirmed<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.apfelpatient.de\/en\/news\/apple-under-pressure-italy-imposes-multi-million-euro-fine\">Apple under pressure: Italy imposes millions in fines<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.apfelpatient.de\/en\/news\/apple-warns-employees-with-visas-against-traveling-abroad\">Apple warns employees with visas against international travel<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.apfelpatient.de\/en\/news\/data-retention-government-wants-to-store-ip-addresses\">Data retention: Government wants to store IP addresses<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.apfelpatient.de\/en\/news\/apple-tv-cancels-the-last-frontier-after-one-season\">Apple TV cancels &quot;The Last Frontier&quot; after one season<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.apfelpatient.de\/en\/news\/apple-showcases-new-ai-research-on-smartphone-photography\">Apple showcases new AI research on smartphone photography<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.apfelpatient.de\/en\/news\/apple-indirectly-forces-iphone-users-to-update-to-ios-26\">Apple indirectly forces iPhone users to update to iOS 26<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.apfelpatient.de\/en\/news\/samsung-is-entering-the-2nm-era-earlier-with-the-exynos-2600\">Samsung is entering the 2nm era earlier with Exynos 2600<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.apfelpatient.de\/en\/news\/airpods-pro-3-interference-noises-still-unresolved-even-after-updates\">AirPods Pro 3: Background noise persists even after updates<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.apfelpatient.de\/en\/news\/chatgpt-extends-the-chat-history-with-an-important-new-function\">ChatGPT extends the chat history with an important new function<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.apfelpatient.de\/en\/news\/apple-introduces-unigen-1-5-an-ai-model-for-all-images\">Apple introduces UniGen 1.5: An AI model for all images<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.apfelpatient.de\/en\/news\/a-macos-bug-has-caused-studio-display-to-flicker-for-months\">A macOS bug has caused Studio Display to flicker for months<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.apfelpatient.de\/en\/news\/apple-plans-to-introduce-more-advertising-in-app-store-search-starting-in-2026\">Apple plans to increase advertising in App Store search starting in 2026<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.apfelpatient.de\/en\/news\/chatgpt-now-supports-apple-music-directly-in-the-app\">ChatGPT now supports Apple Music directly within the app<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.apfelpatient.de\/en\/news\/apple-opens-app-store-in-japan-and-changes-ios-rules\">Apple opens App Store in Japan and changes iOS rules<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.apfelpatient.de\/en\/news\/apple-tv-expands-the-monarch-universe-with-a-new-spin-off\">Apple TV expands Monarch universe with new spin-off<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.apfelpatient.de\/en\/news\/apple-unveils-3d-scenes-from-just-one-photo-with-sharp\">Apple introduces SHARP: 3D scenes from just one photo<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.apfelpatient.de\/en\/news\/apple-stock-morgan-stanley-raises-price-target-to-315\">Apple stock: Morgan Stanley raises price target to $315<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.apfelpatient.de\/en\/news\/the-trump-administration-is-threatening-the-eu-with-retaliation-over-dma\">The Trump administration is threatening the EU with retaliation over DMA<\/a><\/li>\n<\/ul>\n\n\n\n<h6 class=\"wp-block-heading translation-block\" id=\"h-kennt-ihr-schon-unsere-amazon-storefront-dort-findet-ihr-eine-handverlesene-auswahl-von-diversen-produkten-f-r-euer-iphone-und-co-viel-spa-beim-st-bern\"><em>Have you already checked out our Amazon Storefront? You'll find a hand-picked selection of various products for your iPhone and other devices there \u2013 <span class=\"has-inline-color has-vivid-red-color\"><a href=\"https:\/\/www.amazon.de\/shop\/apfelpatientofficial\" class=\"ek-link\" data-wpel-link=\"exclude\" rel=\"follow noopener\" target=\"_self\"><span style=\"text-decoration: underline\" class=\"ek-underline\">enjoy browsing<\/span><\/a>.<\/span><\/em><\/h6>\n\n\n\n<h6 class=\"wp-block-heading translation-block\" id=\"h-der-beitrag-enthalt-partnerlinks\">This post contains <a data-type=\"URL\" data-id=\"https:\/\/www.apfelpatient.de\/partnerprogramm\" href=\"https:\/\/www.apfelpatient.de\/en\/partner-program\" data-wpel-link=\"internal\" target=\"_self\">affiliate links<\/a>.<\/h6>","protected":false},"excerpt":{"rendered":"<p>macOS protection fails: Notarized app secretly downloads malware and bypasses Gatekeeper without any warning message.<\/p>","protected":false},"author":2,"featured_media":62255,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jnews-multi-image_gallery":[],"jnews_single_post":{"format":"standard","override":[{"template":"2","parallax":"1","fullscreen":"1","layout":"right-sidebar","sidebar":"default-sidebar","second_sidebar":"default-sidebar","sticky_sidebar":"1","share_position":"top","share_float_style":"share-monocrhome","show_featured":"1","show_post_meta":"1","show_post_author":"1","show_post_author_image":"1","show_post_date":"1","post_date_format":"default","post_date_format_custom":"Y\/m\/d","show_post_reading_time":"0","post_reading_time_wpm":"300","post_calculate_word_method":"str_word_count","show_zoom_button":"0","zoom_button_out_step":"2","zoom_button_in_step":"3","show_post_tag":"1","show_prev_next_post":"1","show_popup_post":"1","show_comment_section":"1","number_popup_post":"1","show_author_box":"0","show_post_related":"0","show_inline_post_related":"0"}],"image_override":[{"single_post_thumbnail_size":"crop-500","single_post_gallery_size":"crop-500"}],"trending_post_position":"meta","trending_post_label":"Trending","sponsored_post_label":"Sponsored by","disable_ad":"0"},"jnews_primary_category":{"id":"9"},"footnotes":""},"categories":[9],"tags":[4],"class_list":["post-62258","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-macos"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.6 (Yoast SEO v27.6) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>macOS Gatekeeper durch zweistufige Malware-Kette umgangen Apfelpatient<\/title>\n<meta name=\"description\" content=\"macOS Schutz versagt: Notarisierte App l\u00e4dt heimlich Malware nach und umgeht Gatekeeper ohne jede Warnmeldung.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.apfelpatient.de\/en\/news\/macos-gatekeeper-bypassed-through-a-two-stage-malware-chain\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"macOS Gatekeeper durch zweistufige Malware-Kette umgangen\" \/>\n<meta property=\"og:description\" content=\"macOS Schutz versagt: Notarisierte App l\u00e4dt heimlich Malware nach und umgeht Gatekeeper ohne jede Warnmeldung.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.apfelpatient.de\/en\/news\/macos-gatekeeper-bypassed-through-a-two-stage-malware-chain\" \/>\n<meta property=\"og:site_name\" content=\"Apfelpatient\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/apfelpatientOfficial\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/apfelpatientOfficial\" \/>\n<meta property=\"article:published_time\" content=\"2025-12-28T16:42:35+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-12-29T13:32:44+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.apfelpatient.de\/wp-content\/uploads\/2025\/12\/shutterstock_2248466625.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"1067\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Milan\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:description\" content=\"macOS Schutz versagt: Notarisierte App l\u00e4dt heimlich Malware nach und umgeht Gatekeeper ohne jede Warnmeldung.\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Milan\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"NewsArticle\",\"@id\":\"https:\\\/\\\/www.apfelpatient.de\\\/news\\\/macos-gatekeeper-durch-zweistufige-malware-kette-umgangen#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.apfelpatient.de\\\/news\\\/macos-gatekeeper-durch-zweistufige-malware-kette-umgangen\"},\"author\":{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.apfelpatient.de\\\/en\\\/#organization\",\"name\":\"Apfelpatient\",\"url\":\"https:\\\/\\\/www.apfelpatient.de\\\/en\\\/\"},\"headline\":\"macOS Gatekeeper durch zweistufige Malware-Kette umgangen\",\"datePublished\":\"2025-12-28T16:42:35+00:00\",\"dateModified\":\"2025-12-29T13:32:44+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.apfelpatient.de\\\/news\\\/macos-gatekeeper-durch-zweistufige-malware-kette-umgangen\"},\"wordCount\":955,\"publisher\":{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.apfelpatient.de\\\/en\\\/#organization\",\"name\":\"Apfelpatient\",\"url\":\"https:\\\/\\\/www.apfelpatient.de\\\/en\\\/\"},\"image\":{\"@id\":\"https:\\\/\\\/www.apfelpatient.de\\\/news\\\/macos-gatekeeper-durch-zweistufige-malware-kette-umgangen#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.apfelpatient.de\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/shutterstock_2248466625.jpg\",\"keywords\":[\"macOS\"],\"articleSection\":\"News\",\"inLanguage\":\"en-US\",\"copyrightYear\":\"2025\",\"copyrightHolder\":{\"@id\":\"https:\\\/\\\/www.apfelpatient.de\\\/en\\\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.apfelpatient.de\\\/news\\\/macos-gatekeeper-durch-zweistufige-malware-kette-umgangen\",\"url\":\"https:\\\/\\\/www.apfelpatient.de\\\/news\\\/macos-gatekeeper-durch-zweistufige-malware-kette-umgangen\",\"name\":\"macOS Gatekeeper durch zweistufige Malware-Kette umgangen Apfelpatient\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.apfelpatient.de\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.apfelpatient.de\\\/news\\\/macos-gatekeeper-durch-zweistufige-malware-kette-umgangen#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.apfelpatient.de\\\/news\\\/macos-gatekeeper-durch-zweistufige-malware-kette-umgangen#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.apfelpatient.de\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/shutterstock_2248466625.jpg\",\"datePublished\":\"2025-12-28T16:42:35+00:00\",\"dateModified\":\"2025-12-29T13:32:44+00:00\",\"description\":\"macOS Schutz versagt: Notarisierte App l\u00e4dt heimlich Malware nach und umgeht Gatekeeper ohne jede Warnmeldung.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.apfelpatient.de\\\/news\\\/macos-gatekeeper-durch-zweistufige-malware-kette-umgangen#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.apfelpatient.de\\\/news\\\/macos-gatekeeper-durch-zweistufige-malware-kette-umgangen\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.apfelpatient.de\\\/news\\\/macos-gatekeeper-durch-zweistufige-malware-kette-umgangen#primaryimage\",\"url\":\"https:\\\/\\\/www.apfelpatient.de\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/shutterstock_2248466625.jpg\",\"contentUrl\":\"https:\\\/\\\/www.apfelpatient.de\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/shutterstock_2248466625.jpg\",\"width\":1600,\"height\":1067,\"caption\":\"Bild: Shutterstock \\\/ Pungu x\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.apfelpatient.de\\\/news\\\/macos-gatekeeper-durch-zweistufige-malware-kette-umgangen#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Startseite\",\"item\":\"https:\\\/\\\/www.apfelpatient.de\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"macOS Gatekeeper durch zweistufige Malware-Kette umgangen\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.apfelpatient.de\\\/#website\",\"url\":\"https:\\\/\\\/www.apfelpatient.de\\\/\",\"name\":\"Apfelpatient\",\"description\":\"Alles rund um Apple!\",\"publisher\":{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.apfelpatient.de\\\/en\\\/#organization\",\"name\":\"Apfelpatient\",\"url\":\"https:\\\/\\\/www.apfelpatient.de\\\/en\\\/\"},\"alternateName\":\"Apfelpatient\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.apfelpatient.de\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/www.apfelpatient.de\\\/#\\\/schema\\\/person\\\/c379c185d5d95d7b02ccbd6c7bef2759\",\"name\":\"Milan\",\"logo\":{\"@id\":\"https:\\\/\\\/www.apfelpatient.de\\\/#\\\/schema\\\/person\\\/image\\\/\"},\"description\":\"Hallo und herzlich willkommen auf meinem Technik-Blog! Als gro\u00dfer Apple-Fan berichte ich hier \u00fcber alles, was mit Apple zu tun hat: von den neuesten News und spannenden Ger\u00fcchten \u00fcber hilfreiche Tipps und Tricks bis hin zu ausf\u00fchrlichen Produkttests. Wenn du genauso technikbegeistert bist wie ich, bist du hier genau richtig!\",\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/apfelpatientOfficial\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/milan-jovicic-42aa0231b\"],\"url\":\"https:\\\/\\\/www.apfelpatient.de\\\/en\\\/author\\\/apfeladmin\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"macOS Gatekeeper bypassed via two-stage malware chain Apfelpatient","description":"macOS protection fails: Notarized app secretly downloads malware and bypasses Gatekeeper without any warning message.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.apfelpatient.de\/en\/news\/macos-gatekeeper-bypassed-through-a-two-stage-malware-chain","og_locale":"en_US","og_type":"article","og_title":"macOS Gatekeeper durch zweistufige Malware-Kette umgangen","og_description":"macOS Schutz versagt: Notarisierte App l\u00e4dt heimlich Malware nach und umgeht Gatekeeper ohne jede Warnmeldung.","og_url":"https:\/\/www.apfelpatient.de\/en\/news\/macos-gatekeeper-bypassed-through-a-two-stage-malware-chain","og_site_name":"Apfelpatient","article_publisher":"https:\/\/www.facebook.com\/apfelpatientOfficial","article_author":"https:\/\/www.facebook.com\/apfelpatientOfficial","article_published_time":"2025-12-28T16:42:35+00:00","article_modified_time":"2025-12-29T13:32:44+00:00","og_image":[{"width":1600,"height":1067,"url":"https:\/\/www.apfelpatient.de\/wp-content\/uploads\/2025\/12\/shutterstock_2248466625.jpg","type":"image\/jpeg"}],"author":"Milan","twitter_card":"summary_large_image","twitter_description":"macOS Schutz versagt: Notarisierte App l\u00e4dt heimlich Malware nach und umgeht Gatekeeper ohne jede Warnmeldung.","twitter_misc":{"Written by":"Milan","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/www.apfelpatient.de\/news\/macos-gatekeeper-durch-zweistufige-malware-kette-umgangen#article","isPartOf":{"@id":"https:\/\/www.apfelpatient.de\/news\/macos-gatekeeper-durch-zweistufige-malware-kette-umgangen"},"author":{"@type":"Organization","@id":"https:\/\/www.apfelpatient.de\/en\/#organization","name":"Apfelpatient","url":"https:\/\/www.apfelpatient.de\/en\/"},"headline":"macOS Gatekeeper durch zweistufige Malware-Kette umgangen","datePublished":"2025-12-28T16:42:35+00:00","dateModified":"2025-12-29T13:32:44+00:00","mainEntityOfPage":{"@id":"https:\/\/www.apfelpatient.de\/news\/macos-gatekeeper-durch-zweistufige-malware-kette-umgangen"},"wordCount":955,"publisher":{"@type":"Organization","@id":"https:\/\/www.apfelpatient.de\/en\/#organization","name":"Apfelpatient","url":"https:\/\/www.apfelpatient.de\/en\/"},"image":{"@id":"https:\/\/www.apfelpatient.de\/news\/macos-gatekeeper-durch-zweistufige-malware-kette-umgangen#primaryimage"},"thumbnailUrl":"https:\/\/www.apfelpatient.de\/wp-content\/uploads\/2025\/12\/shutterstock_2248466625.jpg","keywords":["macOS"],"articleSection":"News","inLanguage":"en-US","copyrightYear":"2025","copyrightHolder":{"@id":"https:\/\/www.apfelpatient.de\/en\/#organization"}},{"@type":"WebPage","@id":"https:\/\/www.apfelpatient.de\/news\/macos-gatekeeper-durch-zweistufige-malware-kette-umgangen","url":"https:\/\/www.apfelpatient.de\/news\/macos-gatekeeper-durch-zweistufige-malware-kette-umgangen","name":"macOS Gatekeeper bypassed via two-stage malware chain Apfelpatient","isPartOf":{"@id":"https:\/\/www.apfelpatient.de\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.apfelpatient.de\/news\/macos-gatekeeper-durch-zweistufige-malware-kette-umgangen#primaryimage"},"image":{"@id":"https:\/\/www.apfelpatient.de\/news\/macos-gatekeeper-durch-zweistufige-malware-kette-umgangen#primaryimage"},"thumbnailUrl":"https:\/\/www.apfelpatient.de\/wp-content\/uploads\/2025\/12\/shutterstock_2248466625.jpg","datePublished":"2025-12-28T16:42:35+00:00","dateModified":"2025-12-29T13:32:44+00:00","description":"macOS protection fails: Notarized app secretly downloads malware and bypasses Gatekeeper without any warning message.","breadcrumb":{"@id":"https:\/\/www.apfelpatient.de\/news\/macos-gatekeeper-durch-zweistufige-malware-kette-umgangen#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.apfelpatient.de\/news\/macos-gatekeeper-durch-zweistufige-malware-kette-umgangen"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.apfelpatient.de\/news\/macos-gatekeeper-durch-zweistufige-malware-kette-umgangen#primaryimage","url":"https:\/\/www.apfelpatient.de\/wp-content\/uploads\/2025\/12\/shutterstock_2248466625.jpg","contentUrl":"https:\/\/www.apfelpatient.de\/wp-content\/uploads\/2025\/12\/shutterstock_2248466625.jpg","width":1600,"height":1067,"caption":"Bild: Shutterstock \/ Pungu x"},{"@type":"BreadcrumbList","@id":"https:\/\/www.apfelpatient.de\/news\/macos-gatekeeper-durch-zweistufige-malware-kette-umgangen#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Startseite","item":"https:\/\/www.apfelpatient.de\/"},{"@type":"ListItem","position":2,"name":"macOS Gatekeeper durch zweistufige Malware-Kette umgangen"}]},{"@type":"WebSite","@id":"https:\/\/www.apfelpatient.de\/#website","url":"https:\/\/www.apfelpatient.de\/","name":"apple patient","description":"Everything about Apple!","publisher":{"@type":"Organization","@id":"https:\/\/www.apfelpatient.de\/en\/#organization","name":"Apfelpatient","url":"https:\/\/www.apfelpatient.de\/en\/"},"alternateName":"Apfelpatient","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.apfelpatient.de\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/www.apfelpatient.de\/#\/schema\/person\/c379c185d5d95d7b02ccbd6c7bef2759","name":"Milan","logo":{"@id":"https:\/\/www.apfelpatient.de\/#\/schema\/person\/image\/"},"description":"Hello and welcome to my technology blog! As a big Apple fan, I report on everything to do with Apple: from the latest news and exciting rumors to helpful tips and tricks and detailed product tests. If you are as enthusiastic about technology as I am, you have come to the right place!","sameAs":["https:\/\/www.facebook.com\/apfelpatientOfficial","https:\/\/www.linkedin.com\/in\/milan-jovicic-42aa0231b"],"url":"https:\/\/www.apfelpatient.de\/en\/author\/apfeladmin"}]}},"_links":{"self":[{"href":"https:\/\/www.apfelpatient.de\/en\/wp-json\/wp\/v2\/posts\/62258","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.apfelpatient.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.apfelpatient.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.apfelpatient.de\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.apfelpatient.de\/en\/wp-json\/wp\/v2\/comments?post=62258"}],"version-history":[{"count":5,"href":"https:\/\/www.apfelpatient.de\/en\/wp-json\/wp\/v2\/posts\/62258\/revisions"}],"predecessor-version":[{"id":62292,"href":"https:\/\/www.apfelpatient.de\/en\/wp-json\/wp\/v2\/posts\/62258\/revisions\/62292"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.apfelpatient.de\/en\/wp-json\/wp\/v2\/media\/62255"}],"wp:attachment":[{"href":"https:\/\/www.apfelpatient.de\/en\/wp-json\/wp\/v2\/media?parent=62258"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.apfelpatient.de\/en\/wp-json\/wp\/v2\/categories?post=62258"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.apfelpatient.de\/en\/wp-json\/wp\/v2\/tags?post=62258"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}