New MacOS Malware Exploits Legitimate Developer ID to Pose as Apple Crash Reporter
ID: efdf692b-b487-5348-a919-9debc841cf96
STIX ID: report--efdf692b-b487-5348-a919-9debc841cf96
Feed Name: Infosecurity Magazine (News)
CrashStealer is a newly observed macOS infostealer delivered via a notarized, developer-signed disk image (reported as "Werkbit Setup") that impersonates Apple's crash-reporting component to bypass Gatekeeper and trick users into running a dropper; after installation it prompts for system credentials and exfiltrates browser passwords, cryptocurrency wallet logins and keychain data, employing client-side AES-GCM encryption, control-flow flattening, encrypted strings and layered anti-debugging to resist analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
