CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks
ID: 6494f977-f403-52b7-8b2a-ab5403feb8fd
STIX ID: report--6494f977-f403-52b7-8b2a-ab5403feb8fd
Feed Name: The Hacker News
CrashStealer is a sophisticated macOS information stealer distributed via a signed, Apple-notarized disk image ('Werkbit.app') that bypasses Gatekeeper; once executed it persists as a LaunchAgent, validates the local login password to unlock the keychain, harvests credentials from Chromium browsers, ~80 cryptocurrency wallet extensions, 14 password managers, and files from user directories, encrypts collected data with AES-GCM, and exfiltrates archives to an attacker-controlled server (179.43.166.242); operators use re-signing, control-flow flattening, encrypted strings and anti-debugging to resist analysis and the delivery chain indicates a broader multi-platform campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
