New Mac malware masquerades as Apple's crash reporter: 3 ways to dodge the threat
ID: c3e6cc0a-d0b6-556d-a1f7-1cb67af6382f
STIX ID: report--c3e6cc0a-d0b6-556d-a1f7-1cb67af6382f
Feed Name: ZDNet Security
CrashStealer is a recently observed C++ macOS infostealer that impersonates Apple's crash reporter, using signed and notarized .dmg droppers (e.g., CrashReporter.dmg/CrashReporter.app) to clear Gatekeeper and present fake keychain/password prompts; it validates stolen credentials locally, harvests data from password managers, browsers and cryptocurrency wallets, and exfiltrates the data to attacker-controlled servers. Researchers first noted a suspicious VirusTotal upload and report the malware is in the wild, with distribution vectors including disguised disk images, social-engineered "ClickFix" commands, and poisoned AI chatbot links; recommended mitigations are verifying .dmg sources, scrutinizing unexpected password prompts, and keeping macOS updated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
