A polished installer can make risky software feel routine. You see a familiar Mac window, follow the directions and enter your password when asked. By then, the app may already be working against you.
Security researchers at Jamf Threat Labs have uncovered CrashStealer, a new Mac information stealer that impersonates Apple’s crash-reporting software. Jamf first tracked the malware in May 2026 while it appeared to be under development. By early July, researchers detected it in active attacks.
Free live CyberGuy class: Sick of Spam? Join us on July 22.
Join us this Wednesday, July 22, at 1 PM ET for a free CyberGuy Live class that will help you cut down on robocalls, spam texts, junk email and other unwanted messages. Kurt “CyberGuy” Knutsson will walk you step by step through simple ways to filter spam, clean up your inbox and recognize the messages that could put your personal information at risk. No technical experience is needed. Youll also receive our spam-stopping checklist, and every registrant will get a link to the class recording afterward.
Reserve your free spot today at CyberGuyLive.com.
REDHOOK ANDROID MALWARE CAN QUIETLY HIJACK YOUR PHONE
CrashStealer targets information many people rely on every day. It searches for browser credentials, password-manager data and cryptocurrency wallet information. The malware can copy the Mac login Keychain as well. The malware stands out because its developers wrote it in native C++. Many common Mac stealers rely on AppleScript or simpler software wrappers.
CrashStealer also encrypts the files it collects before sending them to an attacker-controlled server. Meanwhile, anti-debugging features make the malware harder for researchers to examine. However, the first app a victim sees isnt called CrashStealer. The attack begins with a disk image branded as “Werkbit Setup.”
The Werkbit Setup disk image contains a polished installer. Its directions tell the user to right-click the app and choose Open. That action often appears in instructions for software that needs to get around a Mac security warning. In this case, the installer already carried a valid Apple Developer ID and a notarization ticket. Therefore, it could clear Gatekeeper on its first launch. Jamf also found that the disk image itself had been signed, which researchers called unusual for malicious Mac delivery.
The website that distributed Werkbit Setup required a meeting PIN. That setup may have helped the attackers limit access to people who received the correct code. It also made the download feel more exclusive and potentially more believable.
Once opened, Werkbit Setup contacted GitHub for an initial command. It then downloaded a script from the attackers’ infrastructure. Next, the script installed a second disk image named CrashReporter.dmg in a hidden temporary folder. The payload used the name CrashReporter and the bundle identifier com.apple.crashreporter. Those details were chosen to resemble an Apple system component. The malware then launched quietly in the background.
Apple uses Gatekeeper alongside Developer ID signing to reduce the risk from downloaded software. Its notarization process checks an app for known malicious content when developers submit it. Gatekeeper can also check whether Apple has revoked the signing certificate. Still, a notarized labe