Researchers replace downloaded macOS apps with evil twins, Apple shrugs

Summary

Researchers have demonstrated a new attack on macOS that replaces downloaded applications with malicious "evil twin" versions. This exploit bypasses Apple's Gatekeeper security feature, allowing attackers to potentially install unauthorized software. Apple has reportedly acknowledged the issue but has not yet implemented a fix.

IFF Assessment

FOE

This article describes a new vulnerability and exploit that can be used to compromise user systems, representing bad news for defenders.

Defender Context

This exploit highlights a significant weakness in macOS Gatekeeper's ability to protect users from malicious downloads. Defenders should be aware of this attack vector and encourage users to be extra cautious about application sources, especially for applications downloaded from unofficial channels. It also points to the ongoing challenge of keeping security features effective against evolving attacker techniques.

Read Full Story →