CrashStealer is a macOS infostealer disguised as a videoconferencing application called Werkbit Setup, which successfully passed Apple's notarization process, allowing it to bypass Gatekeeper defenses. The malware requires users to enter a meeting PIN before downloading, suggesting targeted distribution against pre-selected victims. Once executed, the loader retrieves instructions from GitHub, downloads the CrashStealer payload, and deletes intermediate files while never delivering the promised videoconferencing tool. The malware mimics Apple's CrashReporter tool using the same name, icon, and identifier, then displays a fake system prompt to capture the user's macOS password.
After capturing valid credentials, CrashStealer accesses Keychain to steal stored passwords, cryptographic keys, certificates, and tokens, while also targeting 14 third-party password managers including 1Password, Bitwarden, and LastPass. The malware collects credentials and cookies from Chromium-based browsers and Firefox, and specifically targets data from 80 cryptocurrency wallet extensions such as MetaMask, Phantom, and Coinbase Wallet. It also scans Documents and Downloads folders for interesting files, encrypts all stolen data using AES-256-GCM, and exfiltrates the compressed archive to attacker-controlled servers.
CrashStealer establishes persistence to launch automatically at boot and removes installation traces to hinder detection. Users are advised to research applications before installing, stick to official app stores, use reliable security solutions, and store credentials in secure password managers. The malware was first spotted in development in May 2026 and began operating in the wild by early July. The password prompt immediately validates credentials and reappears if incorrect, making the phishing attempt highly convincing. The attack demonstrates how even notarized applications can bypass Apple's security measures and compromise user data.
Read more...
