# CrashStealer malware disguises as macOS Crash Reporter to steal data

**Published:** 2026-07-15T22:39:14.954Z  
**Topic:** Apple News  
**Sentiment:** neutral  
**Publisher:** TrendWatcher — https://www.trendwatcher.in/article/dbf6c098-8f1e-46f5-a6a7-73492f165061

CrashStealer, a notarized macOS infostealer, bypasses Gatekeeper and extracts credentials from 80 crypto wallets and 14 password managers – learn how it works

CrashStealer, a new macOS infostealer signed with a valid Apple developer ID, masquerades as the system’s CrashReporter and has already harvested credentials from dozens of crypto wallets and password managers, exposing a gap in macOS’s Gatekeeper defenses [1].

**At a glance** |  
|---|---|  
| Malware name | CrashStealer |  
| Distribution method | Signed, notarized “Werkbit Setup” DMG |  
| Data targeted | Keychain, browsers, 80 crypto wallets, 14 password managers |  
| Bypass technique | Valid Developer ID + notarization ticket |  

## How the attack works  
Jamf Threat Labs traced the infection chain to a disk image named “Werkbit Setup” that carries a legitimate‑looking installer called **CrashReporter.app**. Because the dropper is signed with a purchased Apple developer certificate and notarized, macOS Gatekeeper lets it run without warning, a step most infostealers skip due to the cost of a certificate [3]. Once executed, the installer creates a LaunchAgent (`com.apple.crashreporter.helper`) and presents a native‑style password prompt that tricks users into unlocking their Keychain. The malware then exfiltrates the unlocked secrets to a remote server, pulling browser cookies, credentials, and data from more than 80 cryptocurrency wallet extensions and 14 popular password managers such as 1Password and LastPass [1][2].

## Why macOS users should be concerned  
The use of a signed, notarized dropper marks a shift from typical Mac malware, which often relies on unsigned binaries that trigger Gatekeeper alerts. By purchasing a developer certificate, the attackers reduce user friction and increase the likelihood of successful installations, as noted by Jamf’s director Jaron Bradley [3]. The payload’s client‑side AES‑GCM encryption and anti‑debugging tricks further complicate detection, distinguishing CrashStealer from earlier macOS threats like AMOS or MacSync [3]. Although the malware skips large files to keep exfiltration volumes low, the breadth of data it harvests—especially crypto wallet keys—poses a significant financial risk to affected users.

## What to watch  
- **Apple’s response** – Apple revoked the compromised developer ID after Jamf’s report; monitoring any new revocations or policy changes around notarization could indicate broader mitigation efforts.  
- **Distribution channels** – The initial lure appears to be a fake site (“Werkbit Setup”) promoted via social media or search results; tracking similar phishing sites may reveal evolving tactics.  
- **Security updates** – Future macOS releases may tighten Gatekeeper checks for notarized apps; watch for patches that address this bypass vector.  

The emergence of CrashStealer underscores that even macOS’s reputation for strong security can be undermined by attackers willing to invest in legitimate‑looking certificates, forcing users and defenders to scrutinize every installer, even those that appear Apple‑approved.

## Sources
1. Techradar — [This new macOS infostealer poses as an Apple crash reporting tool...](https://www.techradar.com/pro/security/this-new-macos-infostealer-poses-as-an-apple-crash-reporting-tool-to-try-and-steal-all-your-valuable-data)
2. HotHardware — [CrashStealer Malware Poses As Apple Crash Reporter To Hijack Macs](https://hothardware.com/news/crashstealer-malware-hijack-macs)
3. Infosecurity Magazine — [New MacOS Malware Exploits Legitimate Developer ID to Pose as Apple Crash Reporter](https://www.infosecurity-magazine.com/news/macos-malware-apple-crash-reporter/)
4. Sentinelone — [From the Front Lines | New macOS 'covid' Malware Masquerades as...](https://www.sentinelone.com/blog/from-the-front-lines-new-macos-covid-malware-masquerades-as-apple-wears-face-of-apt/)

---
Cite as: TrendWatcher, "CrashStealer malware disguises as macOS Crash Reporter to steal data", https://www.trendwatcher.in/article/dbf6c098-8f1e-46f5-a6a7-73492f165061
