Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

MacRumors

macrumors bot
Original poster


Mac users should watch out for macOS malware called CrashStealer, according to Jamf Threat Labs. The malware impersonates Apple's crash reporting framework, and it's meant to steal all kinds of sensitive information.

bug-security-vulnerability-issue-fix-larry.jpg

CrashStealer collects browser data, password manager data, cryptocurrency wallet extensions, and keychain data, and Jamf first noticed it circulating in a fake Apple-notarized app called Werkbit. With notarization, the malware is not stopped by Gatekeeper, which is part of the macOS security system.

It targets more than 80 cryptocurrency wallet extensions, and 14 password managers like 1Password, LastPass, and Dashlane. It searches through the Document and Downloads folders to look for information worth collecting.

The app looks legitimate and uses a typical macOS install procedure for software downloaded through the web, with the process detailed on Jamf's website. A fake CrashReporter.app is downloaded through Werkbit, and it's meant to impersonate Apple's own crash reporter. A user clicking on the app would likely see it as a legitimate Apple utility.

It requests full disk access "for system administration," and uses a native password prompt that looks like a genuine macOS authorization request. The password entered is used to access the login keychain. Data collected is encrypted with AES–256-GCM through Apple's CommonCrypto and sent to the attacker's IP address.

Jamf says the way CrashStealer was implemented "shows real care," with the concealment steps setting it apart from standard infostealers. The malware was reported to Apple after first being spotted in May and found actively in use in July.

Apple revoked the Werkbit app's signing credentials, so the specific attack vector outlined by Jamf has been disabled, but the malware could surface again. The original version was gated behind a PIN required for installation, suggesting it was aimed at specific people.

Apple's notarization system is meant to protect Mac users from malware, and Apple says that notarized apps are checked for malicious components. CrashStealer makes it clear there are methods for hiding malware from Apple's security process.

When downloading software, users can protect themselves from CrashStealer by being aware that Apple's crash reporter is built-in. Any download that uses CrashReporter is a red flag, as is an app that asks for a system password right when it's launched.

Article Link: CrashStealer Malware Impersonates Apple Tool to Steal Mac Passwords and Crypto
 
People would say for years that Macs can’t get malware, but that was mainly a result of Macs having such a low market share compared to the PC market

That has changed and now Macs are much more susceptible to getting these kinds of malware attacks than they used to be in the past
 
People would say for years that Macs can’t get malware, but that was mainly a result of Macs having such a low market share compared to the PC market

That has changed and now Macs are much more susceptible to getting these kinds of malware attacks than they used to be in the past
It was never true that Macs can't get malware, but macOS is definitely a more popular target now. However, most malware still requires inputting your password because of Apple's multi-layered security, so you need to be careful what things you give access to your password.
 
Honestly I'm surprised crypto is still a thing. I thought that crashed and burned a long time ago. Huh... the more you know...
 
Is there any indication that the free versions of Intego Virus Barrier or Malwarebytes would find this on one's computer???
 
This is a prime example of why I can appreciate Apple’s closed ecosystem for iOS. My iPhone contains more sensitive information than my macBook Pro for this reason. Are there measures Apple can take to prevent malware of this type.
 
  • Like
Reactions: racerhomie
I've looked up on VT for the IoCs, in this case, the .dmg was first submitted on 07-01 to VT. It will probably be flagged by Helmet using its default configuration + VT integration.

 

Attachments

  • Screenshot 2026-07-15 at 22.25.49.png
    Screenshot 2026-07-15 at 22.25.49.png
    321.7 KB · Views: 60
Notarization from Apple is a joke. It in fact gives the user a false sense of security while it is just a registration process based on good will.
What a strange take. Apple has already used their notarization system to disable this installer. I’m not sure how the social engineering of this malware worked but if you install things from the web, it is incumbent on the user to make sure the source is reliable.

No OS vendor can prevent something like this. All they can do is take action once it is reported. Which is exactly what Apple did.
 
Reports of this kind are decidedly unhelpful for nontechnical readers, and probably little use to the technical, either. This payload was apparently attached to an app called "Werkbit," but the story provides no information on this app, how it came to include this code, or why anyone would have downloaded it. Is this merely a proof of concept for a much wider deployment? Could it be attached to other apps, and we simply don't know about it yet? Gosh, wouldn't that be something to know?
 
People would say for years that Macs can’t get malware, but that was mainly a result of Macs having such a low market share compared to the PC market

That has changed and now Macs are much more susceptible to getting these kinds of malware attacks than they used to be in the past
I've never bought this. 250million macs is a fair sized number and mac users tend to have more money than some kid on $500 Windows Metoo
There were over 100million in 2018 which is still rich pickings and definitely worth targeting.
 
Jamf Threat Labs do incredible work. Jamf Protect and Security Cloud are no-brainers for Jamf Pro users, and there’s even a Copilot integration for Defender administrators from Jamf (as they’re a Microsoft security partner too).
 
Plenty of apps and installers can and do ask for authentication during installation and first run so that's not unusual, and I'm not sure I'd distinguish a look-alike crash reporter from Apple's built-in one in the heat of the moment. We are really relying on Apple's vetting plus lesser targeting than Windows to keep exploits in check.
 
Last edited:
  • Like
Reactions: sleven
People would say for years that Macs can’t get malware, but that was mainly a result of Macs having such a low market share compared to the PC market

That has changed and now Macs are much more susceptible to getting these kinds of malware attacks than they used to be in the past
That is simply not true. We never said Mac’s can’t get malware. And it’s been disproven that it was security by obscurity. That’s a tired trope that people love to repeat. But since macOS X was introduced it is sooooo much harder to be infected because everything needs a password to run. So yes Mac’s are inherently more secure than Windows machines. Period.

In the 30+ years I’ve been using macs I got one true self-replicating-without- interaction virus from a Zip disk in 1998 under os9. And as far as I know there are currently still no true virii for macOS but there is of course malware.
 
  • Like
Reactions: zarmanto
I've looked up on VT for the IoCs, in this case, the .dmg was first submitted on 07-01 to VT. It will probably be flagged by Helmet using its default configuration + VT integration.

In my opinion, your post reads like an advertisement for your own app, which in this case, is very bad form.
 
  • Like
Reactions: turbineseaplane
Plenty of apps and installers can and do ask for authentication during installation and first run so that's no unusual, and I'm not sure I'd distinguish a look-alike crash reporter from Apple's built-in one in the heat of the moment. We are really relying on Apple's vetting plus lesser targeting than Windows to keep exploits in check.
That is true.

In my opinion, the biggest takeaway about this is making sure one only downloads / opens apps from verified sources. If I had doubts about an app, its origin, or website found, I would lean into MR for possible answers given the vast community ability for intel and experience.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.