# T1553.001 Gatekeeper Bypass

> As of 2026-10-05, T1553.001 (Gatekeeper Bypass) appears in 20 tracked threats, first reported 2026-06-01 and most recently 2026-10-02, with linked actors including Jade Sleet; it most often appears alongside T1059.004 (Unix Shell).

- **Tracked threats:** 20 (20 high)
- **First seen:** 2026-06-01
- **Last seen:** 2026-10-02
- **Threat actors:** 1
- **Detection rules:** 37 (counts only; Blue tier and above)

## Key facts

- **ID:** T1553.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Defense Impairment
- **Matrix:** Enterprise
- **Parent:** T1553
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1553/001/

## Activity timeline

T1553.001 first appeared in tracked threats on 2026-06-01 and was most recently reported on 2026-10-02. The busiest month was 2026-09 with 6 reports, and 20 of the 20 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1553.001 Gatekeeper Bypass is catalogued by MITRE ATT&CK under the Defense Impairment tactic in the Enterprise matrix, as a sub-technique of [T1553 Subvert Trust Controls](https://intel.threadlinqs.com/technique/T1553). Threadlinqs maps 20 of 2623 tracked threats (0.8%) to it; by severity that is 20 high.

Threats that use T1553.001 most often also use [T1059.004 Unix Shell](https://intel.threadlinqs.com/technique/T1059.004) (17 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (15 threats), [T1543.001 Launch Agent](https://intel.threadlinqs.com/technique/T1543.001) (15 threats), [T1555.001 Keychain](https://intel.threadlinqs.com/technique/T1555.001) (15 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (14 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

1 tracked threat actor appear in the threats that use T1553.001; the most frequent are [Jade Sleet](https://intel.threadlinqs.com/actor/Jade%20Sleet) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1553.001.

- [M1038 Execution Prevention](https://attack.mitre.org/mitigations/M1038/)

## Data sources

Telemetry that can reveal T1553.001, per MITRE ATT&CK.

- Command — Command Execution
- File — File Metadata, File Modification
- Process — Process Creation

## Threat actors using it

- [Jade Sleet](https://intel.threadlinqs.com/actor/Jade%20Sleet) — 1

## Tracked threats

20 tracked threats use T1553.001.

- [Atomic macOS (AMOS) Stealer Delivered via Malicious Ad Impersonating Claude Code (ClickFix-style)](https://intel.threadlinqs.com/threat/TL-2026-2916) — high — 2026-10-02
- [CloudSyncD macOS Backdoor Delivered via Fake Zoom Installer](https://intel.threadlinqs.com/threat/TL-2026-2840) — high — 2026-10-02
- [MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud Calendars as C2 Dead-Drop in Fake "Toria" Crypto…](https://intel.threadlinqs.com/threat/TL-2026-2723) — high — 2026-09-27
- [PamStealer macOS Infostealer Adds Live C2 with X25519 Key Exchange, Four-Method Persistence](https://intel.threadlinqs.com/threat/TL-2026-2674) — high — 2026-09-26
- [MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar…](https://intel.threadlinqs.com/threat/TL-2026-2637) — high — 2026-09-24
- [Macfinger ClickFix Campaign Delivers Atomic macOS Stealer (AMOS) via Fake Verification Prompts](https://intel.threadlinqs.com/threat/TL-2026-2622) — high — 2026-09-23
- [Trusted AI Platforms Weaponized as Malware Distribution Channels: Claude Artifacts, ChatGPT, and Grok Abused…](https://intel.threadlinqs.com/threat/TL-2026-2604) — high — 2026-09-21
- [Jade Sleet (North Korea) Compromises Indian IT Provider via FLATROOF and ROOFDECK macOS Backdoors](https://intel.threadlinqs.com/threat/TL-2026-2599) — high — 2026-09-21
- [Fake OpenAI Codex Download Pages on Google Sites Deliver ClickFix macOS Stealer Tied to Atomic Stealer…](https://intel.threadlinqs.com/threat/TL-2026-2138) — high — 2026-08-25
- [Go-Based macOS Stealer Uses ClickFix Lures to Drain Cryptocurrency Wallets (Aeza Group Infrastructure)](https://intel.threadlinqs.com/threat/TL-2026-2066) — high — 2026-08-18
- [Operation ASTERIX: AI-Assisted Crypto Wallet Phishing/Vishing Fraud Pipeline Abuses Claude Code and Kimi](https://intel.threadlinqs.com/threat/TL-2026-2056) — high — 2026-08-18
- [AmnesiaStealer: macOS Infostealer Hijacks Live Browser Sessions via Chrome DevTools Protocol Remote Control](https://intel.threadlinqs.com/threat/TL-2026-2029) — high — 2026-08-16
- [ClickFix Attacks Deliver Go-Based macOS Infostealer Targeting Crypto Wallets and Keychain Data](https://intel.threadlinqs.com/threat/TL-2026-1936) — high — 2026-08-07
- [SHub Stealer "Reaper" — macOS Infostealer Using applescript:// URL-Scheme Delivery, Filegrabber Module, and…](https://intel.threadlinqs.com/threat/TL-2026-1475) — high — 2026-07-18
- [PamStealer: Rust-Based macOS Infostealer Masquerades as Maccy Clipboard Manager, Validates Stolen Passwords…](https://intel.threadlinqs.com/threat/TL-2026-1104) — high — 2026-07-05
- [Verified X Ad Spreads Mac Infostealer (Atomic Stealer Variant "MacSync"/DigitStealer) via Fake DynamicLake…](https://intel.threadlinqs.com/threat/TL-2026-1095) — high — 2026-07-03
- [macOS ClickFix Campaign Silently Mounts Malicious DMGs (hdiutil attach -nobrowse) to Deploy Atomic macOS…](https://intel.threadlinqs.com/threat/TL-2026-0923) — high — 2026-06-23
- [Meow Mac Stealer RAT: macOS ClickFix Lures Deploy AppleScript Infostealer with Persistent RAT Capabilities](https://intel.threadlinqs.com/threat/TL-2026-0842) — high — 2026-06-17
- [JoseCmanXD Rust Crypto Clipboard Hijacker ("silke"/"silkebin") Distributed via Fake Reputation Across…](https://intel.threadlinqs.com/threat/TL-2026-0840) — high — 2026-06-17
- [Fake BlueWallet macOS Stealer — AppleScript Dropper Delivers Infostealer with Clipboard Crypto-Address…](https://intel.threadlinqs.com/threat/TL-2026-0648) — high — 2026-06-01

## Detection coverage

Threadlinqs maintains 37 detection rules mapped to T1553.001 (SPL 13, KQL 15, Sigma 9). Rule content is available to Blue tier accounts and above; this page shows counts only.

37 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1553 Subvert Trust Controls](https://intel.threadlinqs.com/technique/T1553) — 160 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1553.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
