CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks

A newly discovered macOS malware, dubbed CrashStealer, is making headlines for its unique ability to bypass Gatekeeper checks and infect even the most secure Macs. What’s more alarming is that this malware uses a notarized dropper, which means it can evade many built-in security features designed to protect macOS users.

CrashStealer has been observed in the wild, targeting organizations and individuals who use popular productivity software such as Microsoft Office and Google Chrome. The malware’s primary goal is to steal sensitive information, including login credentials and credit card details, from infected systems. It achieves this by injecting malicious code into running applications, allowing it to siphon off valuable data.

But what exactly makes CrashStealer so formidable? At its core, the malware uses a sophisticated technique called “code injection” to inject malicious code into legitimate processes. This allows it to remain undetected for longer periods and gain access to sensitive areas of an infected system. To make matters worse, CrashStealer’s developers have cleverly wrapped this malicious code in a notarized dropper – essentially a signed container that macOS sees as harmless.

A notarized dropper is typically created by software developers who want to distribute their apps on the App Store or through other channels. The developer submits the app for notarization, which involves Apple’s review process and verification of the app’s digital signature. Once notarized, the dropper can be distributed freely without raising any red flags with Gatekeeper – a built-in security feature designed to prevent malicious apps from running on Macs.

CrashStealer’s use of a notarized dropper highlights the ongoing cat-and-mouse game between cybercriminals and cybersecurity experts. While Apple’s notarization process is intended to ensure that only trusted software reaches users, it can also be exploited by sophisticated attackers like those behind CrashStealer. This serves as a stark reminder that even the most secure systems are not immune to malware threats.

To protect themselves from such threats, macOS users should remain vigilant about the apps they download and install. Be cautious of apps with suspicious or unfamiliar digital signatures, and always check the developer’s reputation before installing any new software. Furthermore, regularly updating your operating system and installed apps is crucial in staying ahead of emerging threats like CrashStealer.

In conclusion, the emergence of CrashStealer serves as a wake-up call for organizations and individuals to reassess their cybersecurity posture. By being aware of the latest threats and taking proactive measures to protect themselves, users can minimize the risk of falling victim to sophisticated malware attacks like this one.


Source: The Hacker News — 2026-07-13