/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researcher finds a macOS adware campaign using malware notarized by Apple; after being notified, Apple shut it down, but then another notarized variant emerged

The ubiquitous Shlayer adware has picked up a new trick, slipping past Cupertino's “notarization” defenses for the first time.

Wired Lily Hay Newman

Context & Ripple Effects

Shlayer is not a newcomer: Kaspersky attributed roughly 30% of all macOS malware detections in 2019 to the trojan, which spreads through fake app installs. What changed with this Wired report is the vector — for the first time, Shlayer variants carried Apple's own notarization seal, the credential Gatekeeper presents to users as proof an app has been vetted.

The episode also previews the cat-and-mouse that followed: researchers later found a months-long flaw that let unnotarized apps run anyway, patched only in Big Sur 11.3, and fresh campaigns like Silver Sparrow on at least 30K Macs kept arriving with native M1 builds. Notarization is clearly being stress-tested from multiple directions.

First-order effects

  • Apple's revocation killed the original notarized build, but the immediate emergence of a second notarized variant means every Mac user who trusts the notarization badge during install was exposed twice — and revocation only helps users who update before running the app.

Second-order effects

  • Adware operators now treat notarization as a hurdle to be re-cleared rather than a wall, forcing Apple to tighten scrutiny of developer-account submissions — friction that lands on legitimate developers whose apps wait behind the same review queue.
  • Each successful bypass raises the value of macOS-focused research and third-party endpoint tools, since the platform's built-in trust signals can no longer be treated as sufficient by enterprise buyers.

Third-order effects

  • If notarized malware keeps recurring alongside structural gaps like the unnotarized-apps flaw, Apple's 'curated platform equals safe' positioning erodes, pushing macOS toward the layered third-party security market Windows users have long taken for granted.

The trend: As Mac malware volume climbs — from Shlayer's dominance in 2019 to M1-native campaigns like Silver Sparrow — Apple's gatekeeping model is shifting from a single vetting gate to a continuous arms race with adversaries who iterate faster than revocations.

Discussion

  • @patrickwardle Patrick Wardle on x
    ❌ 🎮 games bad? ✅ 👾 malware good? ...ughh 2020 really confuses me 😕 #FreeFortnite New blog post: https://objective-see.com/... 🤦‍♂️ 🤬
  • @gayrobot_ @gayrobot_ on x
    I don't understand how an application that was NOT submitted by Adobe as an installer for a DISCONTINUED product gets NOTARIZED! This doesn't instill confidence at all. https://twitter.com/...
  • @reneritchie Rene Ritchie on x
    Well, not malware .app but apps containing malicious adware code. Cat-and-mouse “games” by definition have fully functional cats and mice. With notarization, if a mouse slips through, the cat has a big red (inorganic!) mouse-terminating button it can hit even after the fact. http…
  • @wietze @wietze on x
    Great work by @patrickwardle. Lessons learned: 👾macOS is not immune to malware - you are probably underestimating this risk 📈Non-Windows threats are demonstrably on the rise 🛡️Stay ahead of the game: defend your non-Windows assets with the same rigour https://objective-see.com/..…
  • @caseynewton Casey Newton on x
    Apple generally doesn't consider it malware unless it tells you how to sign up for Netflix outside the app https://twitter.com/...
  • @wired @wired on x
    In February Apple began “notarizing” all macOS applications, in an attempt to weed out illegitimate or malicious apps. But the ubiquitous Shlayer adware has picked up a new trick, slipping past Cupertino's “notarization” defenses for the first time. https://www.wired.com/...
  • @patrickbeuth Patrick Beuth on x
    Apple: “Notarization gives users more confidence that [...] software [...] has been checked by Apple for malicious components.” @patrickwardle: “Hold my Kava”. https://objective-see.com/...
  • @aminsabeti @aminsabeti on x
    Two digital security researchers found a malware campaign disguised as an Adobe Flash installer that had code notarized by Apple and would run on Macs! 😳👀 https://techcrunch.com/...
  • @adam_k_levin Adam Levin on x
    The ubiquitous Shlayer adware has picked up a new trick, slipping past Apple's “notarization” defenses for the first time. https://www.wired.com/...