Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CrashStealer, a new infostealer for macOS: how it works and how to stay safe | Kaspersky official blog

0
Medium
Vulnerabilitymacos
Published: 08/03/2026 (08/03/2026, 14:01:21 UTC)
Source: Kaspersky Security Blog

Description

CrashStealer is a macOS infostealer malware disguised as a videoconferencing app that bypasses Apple's Gatekeeper by using a valid Apple developer certificate and notarization. It tricks users into entering their macOS password via a convincing fake system prompt, then steals credentials from Keychain, multiple third-party password managers, browser passwords and cookies, crypto wallet extensions, and files from Documents and Downloads folders. The stolen data is encrypted and sent to attackers. The malware establishes persistence and removes traces to evade detection. It was distributed via a site posing as a legitimate video conferencing platform requiring a meeting PIN, likely targeting specific victims.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/03/2026, 14:14:50 UTC

Technical Analysis

CrashStealer is a macOS infostealer malware that masquerades as the built-in CrashReporter tool and is delivered through a fake videoconferencing app called Werkbit. The initial installer is signed with a valid Apple developer certificate and notarized, allowing it to bypass macOS Gatekeeper protections. After installation, the malware fetches its payload from attacker-controlled servers and runs without user suspicion. It displays a fake macOS password prompt to capture user credentials, which it verifies before proceeding. CrashStealer then accesses and steals data from the macOS Keychain, 14 popular third-party password managers, credentials and cookies from Chromium-based and Firefox browsers, and data from 80 crypto wallet extensions. It also scans user Documents and Downloads folders for files of interest. The stolen data is encrypted with AES-256-GCM and exfiltrated to the attackers. The malware establishes persistence by copying itself to launch at system startup and deletes installation traces to avoid detection. Distribution is controlled via a meeting PIN mechanism, limiting victims to pre-selected targets. The malware was first observed in May 2026 and active in the wild by July 2026. Kaspersky detects it with heuristics under HEUR:Trojan-Downloader.OSX.Agent.gen and HEUR:Trojan-PSW.OSX.Agent.gen.

Potential Impact

CrashStealer compromises macOS systems by stealing a wide range of sensitive information including system Keychain credentials, data from multiple third-party password managers, browser passwords and cookies, crypto wallet extension data, and user documents. This can lead to credential theft, unauthorized access to user accounts, financial theft especially from cryptocurrency wallets, and exposure of private documents. The malware evades macOS built-in defenses by abusing notarization and developer certificates, and uses social engineering to capture passwords. Persistence and anti-forensic measures make detection and removal more difficult.

Mitigation Recommendations

No official patch or fix is available as this is malware rather than a software vulnerability. Users should avoid downloading software from untrusted sources and verify applications before installation. Sticking to official app stores and verified developers reduces risk. Using reliable security solutions that detect and block malware like CrashStealer is recommended. Users should be cautious of unexpected password prompts and avoid entering credentials unless certain of legitimacy. Keeping credentials in secure password managers not targeted by this malware can reduce impact. Kaspersky security products detect this malware with heuristic signatures. Regular backups and monitoring for unusual system behavior can aid recovery.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.kaspersky.com/blog/crashstealer-werkbit-macos-infostealer/56217/","fetched":true,"fetchedAt":"2026-08-03T14:14:38.099Z","wordCount":1475}

Threat ID: 6a70a24ebf32cb7a34b4637c

Added to database: 08/03/2026, 14:14:38 UTC

Last enriched: 08/03/2026, 14:14:50 UTC

Last updated: 08/03/2026, 17:27:06 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses