Anyone can sign up for the Apple Developer Program to become an "identified developer", so there's nothing that stops an attacker from signing their malware.
I have to admit that Windows' UAC is better in that regard, as it shows the signees name. But of course this is only useful if you know the "right" name.
[0] http://researchcenter.paloaltonetworks.com/2016/03/new-os-x-...
(There is third party tool named RB App Checker which does make these tasks a bit easier, though)
――――――
¹ — https://en.wikipedia.org/wiki/Installer_(OS_X)
² — http://f.cl.ly/items/1s1E3n19273M1l3i3S2X/developer_id_insta...