logo

CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper

ID: 734a3950-63e8-529a-a38e-6abd82751773

STIX ID: report--734a3950-63e8-529a-a38e-6abd82751773

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-07-14

Date Updated: 2026-07-19

Author: Pierluigi Paganini

...
...

CrashStealer is a sophisticated macOS infostealer delivered via a signed and notarized dropper (Werkbit.app) that bypasses Gatekeeper, fetches and re-signs a payload (CrashReporter.app), prompts victims for passwords to unlock keychains, harvests browser credentials, ~80 crypto wallet extensions and multiple password managers, stages and AES-256-GCM encrypts collected artifacts, persists via a LaunchAgent, and employs control-flow flattening, encrypted strings, and anti-debugging; defenders can hunt for .zx_*.zip archives under ~/.cache/com.apple.crashreporter/ and block known domains/IPs and the reported Developer Team ID.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.