Activity timeline
T1553.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-09 with 6 reports, and 20 of the 20 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1553.001 Gatekeeper Bypass is catalogued by MITRE ATT&CK under the Defense Impairment tactic in the Enterprise matrix, as a sub-technique of T1553 Subvert Trust Controls. Threadlinqs maps 20 of 2623 tracked threats (0.8%) to it; by severity that is 20 high.
Threats that use T1553.001 most often also use T1059.004 Unix Shell (17 threats), T1005 Data from Local System (15 threats), T1543.001 Launch Agent (15 threats), T1555.001 Keychain (15 threats), T1036.005 Match Legitimate Resource Name or Location (14 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
1 tracked threat actor appear in the threats that use T1553.001; the most frequent are Jade Sleet (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1553.001.
Data sources
Telemetry that can reveal T1553.001, per MITRE ATT&CK.
- Command — Command Execution
- File — File Metadata, File Modification
- Process — Process Creation
Threat actors using it
Tracked threats
20 tracked threats use T1553.001.
- Atomic macOS (AMOS) Stealer Delivered via Malicious Ad Impersonating Claude Code (ClickFix-style)high
- CloudSyncD macOS Backdoor Delivered via Fake Zoom Installerhigh
- MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud Calendars as C2 Dead-Drop in Fake "Toria" Crypto…high
- PamStealer macOS Infostealer Adds Live C2 with X25519 Key Exchange, Four-Method Persistencehigh
- MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar…high
- Macfinger ClickFix Campaign Delivers Atomic macOS Stealer (AMOS) via Fake Verification Promptshigh
- Trusted AI Platforms Weaponized as Malware Distribution Channels: Claude Artifacts, ChatGPT, and Grok Abused…high
- Jade Sleet (North Korea) Compromises Indian IT Provider via FLATROOF and ROOFDECK macOS Backdoorshigh
- Fake OpenAI Codex Download Pages on Google Sites Deliver ClickFix macOS Stealer Tied to Atomic Stealer…high
- Go-Based macOS Stealer Uses ClickFix Lures to Drain Cryptocurrency Wallets (Aeza Group Infrastructure)high
- Operation ASTERIX: AI-Assisted Crypto Wallet Phishing/Vishing Fraud Pipeline Abuses Claude Code and Kimihigh
- AmnesiaStealer: macOS Infostealer Hijacks Live Browser Sessions via Chrome DevTools Protocol Remote Controlhigh
- ClickFix Attacks Deliver Go-Based macOS Infostealer Targeting Crypto Wallets and Keychain Datahigh
- SHub Stealer "Reaper" — macOS Infostealer Using applescript:// URL-Scheme Delivery, Filegrabber Module, and…high
- PamStealer: Rust-Based macOS Infostealer Masquerades as Maccy Clipboard Manager, Validates Stolen Passwords…high
- Verified X Ad Spreads Mac Infostealer (Atomic Stealer Variant "MacSync"/DigitStealer) via Fake DynamicLake…high
- macOS ClickFix Campaign Silently Mounts Malicious DMGs (hdiutil attach -nobrowse) to Deploy Atomic macOS…high
- Meow Mac Stealer RAT: macOS ClickFix Lures Deploy AppleScript Infostealer with Persistent RAT Capabilitieshigh
- JoseCmanXD Rust Crypto Clipboard Hijacker ("silke"/"silkebin") Distributed via Fake Reputation Across…high
- Fake BlueWallet macOS Stealer — AppleScript Dropper Delivers Infostealer with Clipboard Crypto-Address…high
Detection coverage
Threadlinqs maintains 37 detection rules mapped to T1553.001 (SPL 13, KQL 15, Sigma 9). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1553 Subvert Trust Controls — 160 tracked threats at the technique level.