CrashStealer is a macOS information-stealing malware family implemented primarily in native C++ that masquerades as Apple’s CrashReporter component to harvest sensitive user data. It emerged in 2026 and has been observed progressing from development-stage samples into active operations. The malware is associated with targeted delivery through a trojanized installer posing as a videoconferencing application, with distribution gated in some cases to selected victims. Its delivery chain has abused a valid Apple Developer ID and Apple notarization to reduce Gatekeeper friction, after which a staged loader retrieves and launches the final payload while disguising it as a legitimate Apple crash-reporting utility.
Once executed, CrashStealer presents a native-looking macOS authorization prompt to capture the victim’s login password, validates the credential locally, and uses it to unlock the login Keychain. It then steals browser-stored credentials and cookies, Keychain material, data from numerous cryptocurrency wallet extensions, and records from multiple third-party password managers. It also collects selected user files from common document locations. Stolen data is encrypted client-side with AES-256-GCM, packaged for collection, and exfiltrated to attacker-controlled infrastructure.
CrashStealer also establishes persistence on macOS by copying itself and installing a LaunchAgent while continuing to impersonate Apple software. The malware includes multiple anti-analysis and defense-evasion features, including encrypted strings, control-flow obfuscation, anti-debugging checks, and checks for security or analysis tools. Researchers have noted tradecraft overlap with other macOS stealers such as Atomic Stealer and MacSync, but CrashStealer is distinguished by its native C++ implementation, notarized delivery chain, and layered anti-analysis protections. The malware appears financially motivated and is especially relevant to users with browser-stored credentials, password-manager data, and cryptocurrency assets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
After the application is executed, the initial loader retrieves a shell script hosted on GitHub infrastructure. Once several layers of Base64 encoding have been decoded, the script downloads the primary malicious payload onto the system.
Interestingly, it carries a valid Apple developer certificate and has successfully passed Apple’s notarization process — meaning it cleared the automated prescan for malicious code. As a result, the attackers manage to bypass the operating system’s built-in Gatekeeper defense.
Use the previously captured credentials to gain access to Keychain, the built-in macOS password manager.
To establish persistence on the compromised system, the malware creates a copy of itself, re-signs the file using an ad hoc signature and installs a LaunchAgent under the label com.apple.crashreporter.helper.
Create a copy of itself and establish persistence to launch automatically every time macOS boots.
Persistence is established through familiar macOS mechanisms... creating a LaunchAgent named com.apple.crashreporter.helper... LaunchAgent configuration ensures execution during user logon while automatically restarting the malware should the process terminate unexpectedly.
CrashStealer validates victim credentials before initiating large-scale collection activities... the malware invokes legitimate macOS directory service utilities using dscl -authonly to verify credentials locally. Invalid passwords trigger repeated authentication prompts until the victim provides valid credentials.
Use the previously captured credentials to gain access to Keychain, the built-in macOS password manager.
To establish persistence on the compromised system, the malware creates a copy of itself, re-signs the file using an ad hoc signature and installs a LaunchAgent under the label com.apple.crashreporter.helper.
Create a copy of itself and establish persistence to launch automatically every time macOS boots.
Persistence is established through familiar macOS mechanisms... creating a LaunchAgent named com.apple.crashreporter.helper... LaunchAgent configuration ensures execution during user logon while automatically restarting the malware should the process terminate unexpectedly.
What sets it apart from the commodity stealer crowd is less what it collects than how it is built: client-side AES-GCM encryption of the collected files, and an emphasis on analysis resistance through control-flow flattening, encrypted strings and layered anti-debugging
A new form of malware is targeting macOS users by impersonating Apple’s built-in crash-reporting component to trick victims into installing a password-stealing payload.
Delete temporary files and other installation traces to make detection much harder.
Use the previously captured credentials to gain access to Keychain, the built-in macOS password manager.
Interestingly, it carries a valid Apple developer certificate and has successfully passed Apple’s notarization process — meaning it cleared the automated prescan for malicious code. As a result, the attackers manage to bypass the operating system’s built-in Gatekeeper defense.
CrashStealer retrieves them dynamically and reconstructs them through Base64 decoding before execution.
Crucially, this disk image is signed with a valid Apple developer ID and a notarization ticket, which enables it to clear Apple Gatekeeper, the macOS security feature designed to prevent malware execution on first launch.
Check the computer for installed security tools and malware analysis software.
What sets it apart from the commodity stealer crowd is less what it collects than how it is built: client-side AES-GCM encryption of the collected files, and an emphasis on analysis resistance through control-flow flattening, encrypted strings and layered anti-debugging
CrashStealer validates victim credentials before initiating large-scale collection activities... the malware invokes legitimate macOS directory service utilities using dscl -authonly to verify credentials locally. Invalid passwords trigger repeated authentication prompts until the victim provides valid credentials.
CrashStealer moves towards its true goal: stealing usernames, passwords and any other credentials stored in the browser, as well as stealing logins for cryptocurrency wallets, password managers and other keychain data
In addition, the malware collects all credentials and cookies stored in Chromium-based browsers — Chrome, Brave, Edge, Opera, Opera GX, Vivaldi, Chromium, and NAVER Whale — as well as Firefox.
the malware is designed to collect ... information maintained by password managers
CrashStealer validates victim credentials before initiating large-scale collection activities... the malware invokes legitimate macOS directory service utilities using dscl -authonly to verify credentials locally. Invalid passwords trigger repeated authentication prompts until the victim provides valid credentials.
CrashStealer also incorporates a dedicated file-search component that recursively searches user directories such as Documents and Downloads while intentionally excluding directories unlikely to contain valuable information.
Check the computer for installed security tools and malware analysis software.
What sets it apart from the commodity stealer crowd is less what it collects than how it is built: client-side AES-GCM encryption of the collected files, and an emphasis on analysis resistance through control-flow flattening, encrypted strings and layered anti-debugging
39 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a comparable macOS stealer family in background discussion.
Referenced as a similar macOS stealer for comparison only.
Referenced as another macOS infostealer with overlapping objectives for comparison to AmnesiaStealer.
Mentioned for comparison as another stealer with similar objectives.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.