AUTO-UPDATED

CrashStealer malware masquerades as Apple’s crash report tool to raid your Mac

A new macOS malware strain called CrashStealer disguises itself as a legitimate Apple system utility to trick users into revealing passwords and compromising sensitive data stored on their devices.

Key Points

  • The malware, identified by Jamf Threat Labs, initially spreads through a fake video-meeting application called Werkbit.
  • CrashStealer bypasses Apple’s security checks by using a legitimate, notarized Apple Developer ID to appear as a trusted system process.
  • Once installed, the malware displays a fraudulent password prompt that mimics the official macOS authorization window to steal user credentials.
  • Compromised data includes browser cookies, saved logins, cryptocurrency wallet keys, and information from various password managers.
  • The malware persists on infected systems by installing a LaunchAgent that ensures it restarts automatically every time the user logs in.

Why it Matters

This campaign demonstrates that even notarized software can pose a significant security risk, undermining user trust in Apple’s built-in protection mechanisms. It highlights the necessity for users to remain vigilant against suspicious prompts, as attackers are increasingly using sophisticated social engineering to bypass automated system defenses.
Cult of Mac Published by Anurag Chawake
Read original