A New macOS Malware Threat Lurks in Disguise as Apple’s Crash Reporting Tool
A sophisticated piece of malware has been making the rounds on the dark web, masquerading as Apple’s crash reporting tool to steal sensitive user data. Dubbed CrashStealer, this malicious software has been designed to evade detection by mimicking the behavior and appearance of a legitimate Apple system component.
Researchers at Jamf, a company that specializes in Apple device management and security solutions, have been tracking CrashStealer since May when it was still in development. However, they observed it being used in attacks in early July, indicating a high level of sophistication and care taken by the attackers to avoid detection.
CrashStealer’s primary objective is to steal sensitive information from infected devices, including login credentials, keychain data, and cryptocurrency wallet extensions. To achieve this, the malware impersonates Apple’s system component by taking on the name ‘CrashReporter.app’ and creating a LaunchAgent with the same name as a legitimate tool. This allows it to bypass Gatekeeper, macOS’s built-in anti-malware feature, without raising any red flags.
Once launched, CrashStealer displays a fake password prompt to trick users into entering their administrator credentials. If the user provides the correct password, the malware uses ‘dscl’ (Directory Service command-line) to validate it locally and unlock the user’s Keychain. The Keychain contains sensitive information such as Safari logins, Wi-Fi passwords, application passwords, private cryptographic keys, certificates, and tokens.
In addition to keychain data, CrashStealer also targets browser credentials and cookies from Chromium-based browsers and Firefox, as well as 80 cryptocurrency wallet extensions and 14 password managers. The malware encrypts the stolen data using the AES-256-GCM algorithm before uploading it to a command-and-control (C2) server.
What sets CrashStealer apart from other infostealers is its use of client-side encryption and native C++ implementation, making it more difficult for security tools to detect and block. The attackers behind this campaign have also taken steps to ensure stealth by using a signed and notarized malware dropper and re-signing the payload for persistence.
The implications of CrashStealer are serious, highlighting the need for users to remain vigilant when it comes to software downloads and updates. It’s essential to remember that legitimate companies like Apple do not require administrator credentials to perform routine tasks or access sensitive information.
In light of this discovery, we urge all macOS users to exercise caution when interacting with unfamiliar software or prompts. Always verify the authenticity of any software before installing it, and be wary of unusual requests for administrator privileges. By staying informed and taking proactive steps to secure our devices, we can reduce the risk of falling victim to sophisticated malware like CrashStealer.
Source: Bleeping Computer — 2026-07-13