logo

This fake Apple app can unlock your Mac’s password vault

ID: 3dd87e67-7617-565b-afc7-97ea9119c6df

STIX ID: report--3dd87e67-7617-565b-afc7-97ea9119c6df

Feed Name: Malwarebytes Blog

Threat Score
72/100

Date Published: 2026-07-15

Date Updated: 2026-07-16

...
...

CrashStealer is a macOS infostealer masquerading as CrashReporter.app that uses an Apple‑notarized installer called “Werkbit Setup” distributed from a PIN‑gated fake site to bypass Gatekeeper. It presents a fake password prompt to unlock the user’s Keychain, harvests browser credentials, cookies, password manager data, crypto wallet extensions, and small user files, then exfiltrates the data in AES‑encrypted bundles; Malwarebytes detects it as MacOS.Stealer.Crash. The report warns that notarization can be abused and recommends cautious user behavior, verifying installs, using reputable macOS security software, and separating high‑value assets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.