CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper
ID: 734a3950-63e8-529a-a38e-6abd82751773
STIX ID: report--734a3950-63e8-529a-a38e-6abd82751773
Feed Name: Security Affairs
CrashStealer is a sophisticated macOS infostealer delivered via a signed and notarized dropper (Werkbit.app) that bypasses Gatekeeper, fetches and re-signs a payload (CrashReporter.app), prompts victims for passwords to unlock keychains, harvests browser credentials, ~80 crypto wallet extensions and multiple password managers, stages and AES-256-GCM encrypts collected artifacts, persists via a LaunchAgent, and employs control-flow flattening, encrypted strings, and anti-debugging; defenders can hunt for .zx_*.zip archives under ~/.cache/com.apple.crashreporter/ and block known domains/IPs and the reported Developer Team ID.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
