Apple unwittingly authorized this common Mac malware

(Image credit: Future)

Apple’s much-celebrated security system has been found to have mistakenly authorized a Mac malware campaign, allowing it to run free on macOS devices.

Since February, Apple has required all applications running on macOS (including apps sourced from outside the official Mac App Store) to be fully vetted before a user can run the executable file.

However, a Shlayer adware campaign managed to circumvent these tightened security filters, despite remaining largely identical to previous known strains.

Mac malware

Apple has long enjoyed a reputation as manufacturer of the most secure devices around, which have been described as immune to the various cyberthreats facing Windows OS.

However, while it is technically true that malware designed to target Windows devices cannot run on macOS, Apple devices can still be vulnerable to similar threat types.

In this instance, attackers targeted macOS devices with Shlayer adware, designed to intercept browser queries and feed its own ads into search results, generating significant sums in revenue for its operators.

The Mac malware was previously found to be distributed by over 1,000 websites, each of which disguised the download in a slightly different fashion. At its peak, Shlayer was reportedly present on 10% of all Mac computers.

This latest malware campaign was discovered by college student Peter Dantini, who happened across a Shlayer download hosted on a fake Adobe Flash landing page. He was surprised to learn that macOS did not intervene when he deliberately attempted to activate the download, as it is designed to do.

Dantini passed his discovery over to security researcher Patrick Wardle - who recently identified a bug sequence that could be used to hijack Mac devices - to investigate further and liaise with Apple.

“I had been expecting that if someone were to abuse the notarization system it would be something more sophisticated or complex,” said Wardle. 

“But in a way I’m not surprised that it was adware that did it first. Adware developers are very innovative and constantly evolving, because they stand to lose a ton of money if they can’t get around new defenses.”

Apple was notified of the issue on August 28 and claims to have withdrawn the malware’s notarization certificate on the same day.

“Malicious software constantly changes, and Apple’s notarization system helps us keep malware off the Mac and allow us to respond quickly when it’s discovered,” said the firm.

“Upon learning of this adware, we revoked the identified variant, disabled the developer account and revoked the associated certificates. We thank the researchers for their assistance in keeping our users safe.”

However, Wardle found that Shlayer was still alive and kicking two days later, notarized using a different Apple Developer ID. It is currently unclear how Shlayer continues to deceive the application vetting process.

Via WIRED

TOPICS
Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost