A sophisticated macOS malware, dubbed CrashStealer, has been discovered masquerading as Apple’s crash reporting tool. The malware, which was first tracked in May and seen in action this month, is designed to steal sensitive data from infected devices, including credentials, keychain information, and cryptocurrency wallets.
CrashStealer’s creators have gone to great lengths to evade detection, using a notarized malware dropper that bypasses Gatekeeper, the built-in anti-malware on macOS. The payload is delivered via a signed installer called “Werkbit Setup,” which gives it the appearance of legitimacy. Once launched, the malware displays a fake password prompt to convince users they’re authorizing a system operation, allowing the attackers to gain access to the user’s Keychain.
But that’s not all CrashStealer is designed to steal. According to researchers at Jamf, the malware also targets browser credentials and cookies from Chromium-based browsers and Firefox, as well as data from 80 cryptocurrency wallet extensions, including MetaMask and Coinbase Wallet. Additionally, it goes after 14 password managers, such as 1Password and LastPass, and files stored in user directories like Documents and Downloads.
One of the most striking features of CrashStealer is its use of client-side encryption to protect the stolen data. Before exfiltrating the data, the malware encrypts it using the AES-256-GCM algorithm and packages it into hidden ZIP archives for upload to a command-and-control server. This level of sophistication suggests that the attackers are highly motivated and well-resourced.
While CrashStealer shares some similarities with other infostealer families, its unique combination of client-side encryption and native C++ implementation sets it apart. The researchers at Jamf were unable to determine the exact initial distribution method for the malware, but note that the first-stage payload is hosted on a fake software site registered in late June.
The CrashStealer campaign is notable for its care and attention to detail, using techniques like re-signing the payload to evade detection. This level of stealth suggests that the attackers are focused on maximizing their returns with minimal risk. Security teams would do well to take note of this campaign and review their defenses accordingly.
So what can users do to protect themselves? For one, it’s essential to be cautious when downloading software from untrusted sources, even if they appear legitimate. Regularly updating your operating system and applications is also crucial in preventing exploitation by malware like CrashStealer. Additionally, keeping a close eye on your account activity and monitoring for any suspicious behavior can help you detect and respond to potential incidents quickly.
By being vigilant and taking proactive steps to secure their devices, users can significantly reduce the risk of falling victim to sophisticated attacks like CrashStealer.
Source: Bleeping Computer — 2026-07-13