Particle.news
Download on the App Store

CrashStealer Uses Notarized Dropper to Pose as Apple Crash Reporter

Researchers say the signed installer bypassed Gatekeeper and stole Mac passwords to unlock keychains and send encrypted data to attacker servers.

Overview

  • Jamf first flagged suspicious macOS samples in May 2026, and by mid‑July detailed findings from researchers led Apple to revoke the developer certificate used to distribute the dropper.
  • The initial lure is a stapled, notarized disk image called Werkbit Setup that carries a valid Apple Developer ID and a gated download behind a meeting PIN so the installer runs without Gatekeeper warnings.
  • When launched, the malware shows a native‑looking password dialog, verifies the password locally with the dscl tool, caches it, and uses it to unlock and copy the user’s login keychain.
  • CrashStealer harvests browser credentials, cookies, about 80 crypto wallet extensions, 14 password managers and user files, encrypts each item with AES‑256‑GCM, hides results in .zx_*.zip archives, and persists by re‑signing a copy and installing a LaunchAgent named com.apple.crashreporter.helper.
  • Researchers warn the campaign remains active with hardened infrastructure and cross‑platform indicators, so any Mac that ran the installer and had a password entered should be treated as compromised and disconnected, have credentials rotated, and be inspected or rebuilt following published IoCs and remediation guidance.