How the CrashStealer macOS Malware Steals Your Sensitive Data

Learn how the CrashStealer macOS infostealer disguises itself as an Apple tool to access your Keychain, crypto wallets, passwords, and more, bypassing built-in security.

How the CrashStealer macOS Malware Steals Your Sensitive Data
Sarah Collins

Sarah Collins

Computing Editor

Specializes in PCs, laptops, components, and productivity-focused computing tech.

What is CrashStealer and How Does It Trick macOS Users?

CrashStealer is a type of malware targeting macOS users by masquerading as a legitimate Apple crash reporting tool. Distributed through a fake software site, it arrives in a signed and Apple-notarized installer named “Werkbit Setup,” which helps it bypass Apple's Gatekeeper security without alerting users. When run, the malware installs a background process falsely named to resemble an Apple helper service, further concealing its true function.

How Does CrashStealer Extract Your Sensitive Information?

Apple-notarised CrashStealer malware poses as macOS crash-reporting app -  iTnews
Apple-notarised CrashStealer malware poses as macOS crash-reporting app - iTnews

After installation, CrashStealer prompts users with a fake macOS password dialog to unlock the system's Keychain—the secure repository where passwords, private keys, and certificates are stored. Once access is granted, it exfiltrates a wide array of sensitive data:

  • Stored Keychain passwords and private cryptographic keys
  • Browser credentials and cookies from multiple web browsers
  • Data from over 80 cryptocurrency wallet extensions
  • Information from 14 different password managers
  • Other local files of interest

This breadth of data theft significantly increases the risk of identity theft, account compromise, and financial loss. CrashStealer uses client-side encryption and is built in native C++, making it more sophisticated than some other infostealers.

Who Is at Risk and How Can You Protect Yourself?

Any macOS user who downloads software from unofficial sources, especially from newly registered or suspicious websites, could be vulnerable. The malware’s requirement of a PIN before download aims to limit scrutiny and target less savvy users who may trust recommended links on social media or search engines.

To protect yourself:

  1. Only download applications from the official Mac App Store or trusted developers.
  2. Be cautious with any unexpected password prompts—verify their authenticity before entering credentials.
  3. Keep macOS and all software regularly updated to patch known vulnerabilities.
  4. Use reputable antivirus or anti-malware tools to scan new downloads.
  5. Monitor your cryptocurrency wallets and password managers for unauthorized activity.

Key Takeaway: Vigilance Is Critical to Avoid macOS Infostealers

WARNING: New macOS Malware Impersonates Apple's Notarized Installer
WARNING: New macOS Malware Impersonates Apple's Notarized Installer

CrashStealer exemplifies the increasing sophistication of malware targeting macOS by exploiting user trust and built-in security mechanisms. The combination of notarized code signing and social engineering techniques allows such malware to slip past standard defenses. Users must remain vigilant about download sources, question unexpected password prompts, and utilize layered security practices to safeguard their sensitive data.

React to this story

Related Posts