A newly identified macOS infostealer dubbed CrashStealer is being used in active attacks by masquerading as Apple’s crash-reporting utility and abusing a valid Apple Developer ID with notarization to bypass Gatekeeper on first launch. Distributed in a disk image labeled "Werkbit Setup", the malware presents a fake macOS authorization prompt to capture the user’s system password, then steals browser credentials, Keychain data, password manager information, cryptocurrency wallet and extension data, and files from the Documents and Downloads directories.
Researchers said the C++ malware uses a loader to fetch a Base64-obfuscated shell script from GitHub infrastructure, which then downloads the main payload disguised as CrashReporter.app with the bundle identifier com.apple.crashreporter. CrashStealer encrypts stolen data with AES-256-GCM, packages it into ZIP archives, and exfiltrates it to an attacker-controlled server via libcurl; it also establishes persistence by copying and ad hoc re-signing itself before installing a LaunchAgent named com.apple.crashreporter.helper. Analysts also noted anti-debugging and control-flow obfuscation features designed to complicate detection and reverse engineering.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Researchers believe the CrashStealer macOS infostealer had been under development since May before later being used in active attacks.
Public reporting described CrashStealer as a C++-based macOS infostealer delivered as a signed and notarized "Werkbit Setup" disk image that bypasses Gatekeeper, steals credentials and wallet data, exfiltrates encrypted archives, and installs a LaunchAgent for persistence.
Jamf reported discovering CrashStealer after a suspicious sample was uploaded to VirusTotal, leading to identification of the new macOS infostealer impersonating Apple's crash reporter.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cert.gov.az
Open sourcecysecurity.news
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.