logo

New MacOS Malware Exploits Legitimate Developer ID to Pose as Apple Crash Reporter

ID: efdf692b-b487-5348-a919-9debc841cf96

STIX ID: report--efdf692b-b487-5348-a919-9debc841cf96

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2026-07-14

Date Updated: 2026-07-16

...
...

CrashStealer is a newly observed macOS infostealer delivered via a notarized, developer-signed disk image (reported as "Werkbit Setup") that impersonates Apple's crash-reporting component to bypass Gatekeeper and trick users into running a dropper; after installation it prompts for system credentials and exfiltrates browser passwords, cryptocurrency wallet logins and keychain data, employing client-side AES-GCM encryption, control-flow flattening, encrypted strings and layered anti-debugging to resist analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.