Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

New Mac malware disguises itself as CrashReporter

The malware targets browser credentials, password managers, cryptocurrency wallets and data stored in the macOS Keychain.

byAytun Çelebi
July 22, 2026
in Research
Home Research
Share on FacebookShare on TwitterShare on LinkedInShare on WhatsAppShare on e-mail
Google Preferred Source

Jamf Threat Labs reported the discovery of a new Mac information stealer named CrashStealer, which masquerades as Apple’s crash-reporting software. The malware was first tracked in May 2026 during its development phase, with active attacks detected by early July 2026.

CrashStealer is designed to gather sensitive information such as browser credentials, password manager data, and cryptocurrency wallet details, including data from the Mac login Keychain. Uniquely, it is coded in native C++, in contrast to many other Mac stealers that utilize AppleScript.

The malware encrypts the files it collects before transmitting them to an attacker-controlled server. To evade detection, it incorporates anti-debugging features, complicating research efforts. The attack is initiated via a disk image labeled “Werkbit Setup.”

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.

This disk image contains a polished installer that instructs users to right-click and select “Open” to bypass a Mac security warning. The installer possesses a valid Apple Developer ID and notarization, allowing it to pass Apple’s Gatekeeper security measures on first launch.

The website distributing Werkbit Setup required users to enter a meeting PIN, potentially to control access to targeted individuals. Upon execution, Werkbit Setup connects to GitHub, downloads a script, and installs a second disk image called CrashReporter.dmg in a hidden temporary folder. The malware uses the name CrashReporter with the bundle identifier com.apple.crashreporter, which mimics Apple system components.

Apple employs Gatekeeper and notarization processes to mitigate risks posed by downloaded applications. However, Jamf warned that harmful applications can bypass detection, especially if they use trusted installers to deliver different payloads afterward. Following the identification of malicious activity, Jamf reported the developer team behind Werkbit Setup to Apple, but details regarding the number of infections remain undisclosed.

After launching, CrashStealer prompts users for a password in a manner that mimics legitimate macOS prompts. The malware locally verifies the entered password and, if correct, can unlock the login Keychain, allowing further data acquisition.

CrashStealer searches through the Mac’s storage for data from Chromium-based browsers, Safari, Firefox, and various cryptocurrency wallet extensions, including MetaMask and Phantom. Targeting over 80 wallet extensions and 14 password managers, it also uses a file-search tool to seek sensitive documents while avoiding larger installers and media files.

Collected data is stored in hidden folders and encrypted using AES-256-GCM before packaging into hidden ZIP archives for uploading. Additionally, CrashStealer installs itself in the Library cache folder and creates a LaunchAgent for persistence during user login.

Users are advised to exercise caution when downloading installers and to scrutinize any password prompts that arise unexpectedly. Recommendations to prevent this malware include utilizing the Mac App Store, thoroughly confirming developer sources, and being cautious with installers requiring explicit user actions.


Featured image credit

Tags: macMalware

Related Posts

LLMs showed stronger hiring bias than humans

LLMs showed stronger hiring bias than humans

July 22, 2026
AI surge to drive US data centers to use one-fifth of power by 2035

AI surge to drive US data centers to use one-fifth of power by 2035

July 22, 2026
Startup unveils AI model built on oscillators and it could cut energy use by 1,000x

Startup unveils AI model built on oscillators and it could cut energy use by 1,000x

July 21, 2026
Digital transformation of procurement processes: Building a corporate procurement system based on the example of an international industrial holding project

Digital transformation of procurement processes: Building a corporate procurement system based on the example of an international industrial holding project

July 16, 2026
New dark matter theory proposes two particle types

New dark matter theory proposes two particle types

July 14, 2026
Google Dialogflow CX flaw let researchers create rogue agents

Google Dialogflow CX flaw let researchers create rogue agents

July 14, 2026

LATEST NEWS

Kylian Mbappé named EA Sports FC 27 cover star

Anthropic adds screen-recorded teaching feature to Claude AI

Meta adds Xbox Game Pass starter edition to Horizon+ subscriptions

Threads launches new parental supervision tools for teen safety

9 games to leave PS Plus Extra and Premium in August 2026

Substack introduces new AI transparency features

BEST AI MODELS LEADERBOARD

See the best AI models, ranked by intelligence, benchmark results, speed and token price. Find the most suitable LLMs, Text-to-Image, Image Editing, Text-to-Speech, Text-to-Video and Image-to-Video  artificial intelligence model for your tasks and business.

LATEST TOOLS

Amanda AI

InterviewBot

VernAI

MyLoans

Essay Grader AI

Cover Letter AI

Animate Old Photos

Resume.io

MonAI

AIEngine Plugin

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI tools
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies to improve your experience. You can choose to accept or reject them. Visit our Privacy Policy.