A new macOS malware strain called CrashStealer disguises itself as a legitimate Apple system utility to trick users into revealing passwords and compromising sensitive data stored on their devices.
Key Points
- The malware, identified by Jamf Threat Labs, initially spreads through a fake video-meeting application called Werkbit.
- CrashStealer bypasses Apple’s security checks by using a legitimate, notarized Apple Developer ID to appear as a trusted system process.
- Once installed, the malware displays a fraudulent password prompt that mimics the official macOS authorization window to steal user credentials.
- Compromised data includes browser cookies, saved logins, cryptocurrency wallet keys, and information from various password managers.
- The malware persists on infected systems by installing a LaunchAgent that ensures it restarts automatically every time the user logs in.