logo

New Mac malware masquerades as Apple's crash reporter: 3 ways to dodge the threat

ID: c3e6cc0a-d0b6-556d-a1f7-1cb67af6382f

STIX ID: report--c3e6cc0a-d0b6-556d-a1f7-1cb67af6382f

Feed Name: ZDNet Security

Threat Score
70/100

Date Published: 2026-07-15

Date Updated: 2026-07-16

...
...

CrashStealer is a recently observed C++ macOS infostealer that impersonates Apple's crash reporter, using signed and notarized .dmg droppers (e.g., CrashReporter.dmg/CrashReporter.app) to clear Gatekeeper and present fake keychain/password prompts; it validates stolen credentials locally, harvests data from password managers, browsers and cryptocurrency wallets, and exfiltrates the data to attacker-controlled servers. Researchers first noted a suspicious VirusTotal upload and report the malware is in the wild, with distribution vectors including disguised disk images, social-engineered "ClickFix" commands, and poisoned AI chatbot links; recommended mitigations are verifying .dmg sources, scrutinizing unexpected password prompts, and keeping macOS updated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.