By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Oxford HeraldOxford HeraldOxford Herald
  • Home
  • World
  • Europe
  • USA
  • Middle East
  • Asia
  • General
  • Business
  • Entertainment
  • Technology
  • Health
  • Sports
  • Newsroom
  • Opinions
  • Sitemap
Reading: CrashStealer Mac malware steals passwords and wallets
Share
Notification Show More
Font ResizerAa
Oxford HeraldOxford Herald
Font ResizerAa
  • World
  • Travel
  • Science
  • Technology
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Latest

CrashStealer Mac malware steals passwords and wallets

Last updated: July 21, 2026 2:50 pm
RNN
1 week ago
Share
CrashStealer Mac malware steals passwords and wallets
SHARE

A polished installer can make risky software feel routine. You see a familiar Mac window, follow the directions and enter your password when asked. By then, the app may already be working against you.

Security researchers at Jamf Threat Labs have uncovered CrashStealer, a new Mac information stealer that impersonates Apple’s crash-reporting software. Jamf first tracked the malware in May 2026 while it appeared to be under development. By early July, researchers detected it in active attacks.

Free live CyberGuy class: Sick of Spam? Join us on July 22.

Join us this Wednesday, July 22, at 1 PM ET for a free CyberGuy Live class that will help you cut down on robocalls, spam texts, junk email and other unwanted messages. Kurt “CyberGuy” Knutsson will walk you step by step through simple ways to filter spam, clean up your inbox and recognize the messages that could put your personal information at risk. No technical experience is needed. Youll also receive our spam-stopping checklist, and every registrant will get a link to the class recording afterward.

Reserve your free spot today at CyberGuyLive.com.

REDHOOK ANDROID MALWARE CAN QUIETLY HIJACK YOUR PHONE

CrashStealer targets information many people rely on every day. It searches for browser credentials, password-manager data and cryptocurrency wallet information. The malware can copy the Mac login Keychain as well. The malware stands out because its developers wrote it in native C++. Many common Mac stealers rely on AppleScript or simpler software wrappers.

CrashStealer also encrypts the files it collects before sending them to an attacker-controlled server. Meanwhile, anti-debugging features make the malware harder for researchers to examine. However, the first app a victim sees isnt called CrashStealer. The attack begins with a disk image branded as “Werkbit Setup.”

The Werkbit Setup disk image contains a polished installer. Its directions tell the user to right-click the app and choose Open. That action often appears in instructions for software that needs to get around a Mac security warning. In this case, the installer already carried a valid Apple Developer ID and a notarization ticket. Therefore, it could clear Gatekeeper on its first launch. Jamf also found that the disk image itself had been signed, which researchers called unusual for malicious Mac delivery.

The website that distributed Werkbit Setup required a meeting PIN. That setup may have helped the attackers limit access to people who received the correct code. It also made the download feel more exclusive and potentially more believable.

Once opened, Werkbit Setup contacted GitHub for an initial command. It then downloaded a script from the attackers’ infrastructure. Next, the script installed a second disk image named CrashReporter.dmg in a hidden temporary folder. The payload used the name CrashReporter and the bundle identifier com.apple.crashreporter. Those details were chosen to resemble an Apple system component. The malware then launched quietly in the background.

Apple uses Gatekeeper alongside Developer ID signing to reduce the risk from downloaded software. Its notarization process checks an app for known malicious content when developers submit it. Gatekeeper can also check whether Apple has revoked the signing certificate. Still, a notarized labe

Trump calls terrorist Iranian a cancer. Is he finally the one to remove it?
40 Nordstrom Anniversary Sale deals actually worth buying
Restaurants revive retro pricing for anniversaries — but does the trend make cents?
Appeals court blocks Trump admin from holding migrants without bond for over 90 days
MIKE DAVIS: Federal court sets dangerous precendent against 99-year-old judge
TAGGED:latest
Share This Article
Facebook Email Print
Previous Article Lindsey Graham's sister breaks from foreign policy playbook with a different agenda and more top headlines Lindsey Graham’s sister breaks from foreign policy playbook with a different agenda and more top headlines
Next Article Could a paint-on electronic tattoo spot heart attacks? Could a paint-on electronic tattoo spot heart attacks?
about us

Runway News Network (RNN) is a UK-based digital media group operating multiple independent news platforms across the United Kingdom. We provide structured journalism, press syndication and AI-optimised news distribution for organisations seeking national and regional visibility.

  • Sitemap
  • Advertise

Find Us on Socials

Oxford HeraldOxford Herald
© Runway News Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?