Enterprise & Industry

CrashStealer malware targets Macs as fake Apple crash reporter

New signed infostealer bypasses Gatekeeper via notarized .dmg to steal passwords and crypto.

Deep Dive

Security researchers at Jamf have identified a new macOS infostealer dubbed CrashStealer that impersonates Apple's legitimate crash reporting tool. The malware is distributed as a disk image (CrashReporter.dmg) inside a signed and Apple-notarized dropper named 'Werkbit Setup'. Because the dropper carries a valid Developer ID and a stapled notarization ticket, it initially bypasses Gatekeeper on launch, making it appear trustworthy.

Once executed, CrashReporter.app displays a fake password prompt mimicking macOS authorization to unlock the victim's keychain. After validating the stolen credentials locally, the malware targets password managers, browsers, and cryptocurrency wallets, then exfiltrates the data in an encrypted package to an attacker-controlled server. Researchers note the malware has been in development since May and has now been released into the wild. To defend against such threats, users should always verify the source of .dmg files, avoid ClickFix social engineering prompts that ask users to run commands, and be wary of AI-powered chatbot conversations that may lead to malicious downloads.

Key Points
  • CrashStealer uses a signed and Apple-notarized .dmg dropper ('Werkbit Setup') to bypass Gatekeeper on first launch.
  • The malware mimics Apple's crash reporter icon and prompts users for keychain credentials via a fake macOS authorization window.
  • Stolen data includes passwords, browser info, and cryptocurrency wallets, exfiltrated as encrypted packages.

Why It Matters

This signed malware bypasses macOS trusted execution checks, showing even Apple users must verify software sources carefully.

📬 Get the top 10 AI stories daily