Skip to main content

CrashStealer, a new infostealer for macOS: how it works and how to stay safe | Kaspersky official blog

0
Medium
Published: 08/03/2026 (08/03/2026, 14:01:21 UTC)
Source: Kaspersky Security Blog

Description

Mac users have historically trusted their operating system to keep them safe. That peace of mind mostly comes from Apple’s strict control over its ecosystem, and the fact that macOS has historically faced fewer mass attacks than Windows. However, that doesn’t mean Macs are invulnerable: threats do exist, and new ones emerge all the time. Over just the past few weeks, security researchers have published reports on at least two new campaigns that target Apple devices. The malware used in one of the campaigns has been dubbed CrashStealer , while the other is known as ClickLock . Both rely on different tricks to force users into entering their Mac password, which attackers then use to steal account credentials, crypto assets, documents, and much more. In today’s post, we take a close look at how CrashStealer operates — and how to avoid falling victim to it. A videoconferencing app with CrashStealer inside It was back in May 2026 that researchers spotted the first signs this malware was being developed, and by early July, they caught it operating in the wild. The malware earned its name because of its core mechanism: it disguises itself as the macOS built-in crash reporting tool (CrashReporter) while functioning as an infostealer designed to hijack sensitive data. Researchers managed to trace one of the websites users visited to download the malware. The site poses as a legitimate platform for distributing the video conferencing tool Werkbit. According to researchers, this is the site victims used to download Werkbit, which secretly contained the CrashStealer malware loader. Source However, you can’t just visit the site and download the software. Before downloading, visitors are asked to enter a special meeting PIN. This setup likely allows the attackers to limit the distribution scope by targeting only specific, pre-selected victims. Exactly how the cybercriminals choose their targets and deliver the PIN remains unknown. The “lucky” users with a code end up installing the initial malicious payload — named Werkbit Setup. Interestingly, it carries a valid Apple developer certificate and has successfully passed Apple’s notarization process — meaning it cleared the automated prescan for malicious code. As a result, the attackers manage to bypass the operating system’s built-in Gatekeeper defense. This allows the payload to launch without triggering the usual untrusted software warnings. The Werkbit Setup installer is signed with a valid Apple developer certificate and has passed notarization. Source Once launched, Werkbit Setup first reaches out to GitHub. Researchers believe using this popular platform helps attackers blend in by making these initial network requests look far less suspicious to security tools. After retrieving instructions from a GitHub repository, the program connects directly to the attackers’ server to fetch CrashStealer itself. The loader then saves the malware to a temporary macOS folder, launches it, and wipes most of the intermediate setup files. As a result, a fully functional infostealer is up and running within seconds of Werkbit Setup starting. By the way, the user never gets any videoconferencing app. How CrashStealer works Unlike the Werkbit Setup loader, the CrashStealer malware itself isn’t signed with an Apple developer certificate. To keep users from suspecting anything, the malware disguises itself as the built-in macOS crash reporting tool, CrashReporter, by using the exact same name, app identifier, and a similar icon. Once launched, CrashStealer completes a sequence of steps to gain access to sensitive data, establish persistence in the system, and cover its tracks: Remove metadata — including the attribute that flags the app as an internet download. Display a fake system prompt asking for the user’s macOS password. Use the previously captured credentials to gain access to Keychain, the built-in macOS password manager. Check the computer for installed security tools and malware analysis software.…

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/03/2026, 14:14:50 UTC

Technical Analysis

CrashStealer is a macOS infostealer malware that masquerades as the built-in CrashReporter tool and is delivered through a fake videoconferencing app called Werkbit. The initial installer is signed with a valid Apple developer certificate and notarized, allowing it to bypass macOS Gatekeeper protections. After installation, the malware fetches its payload from attacker-controlled servers and runs without user suspicion. It displays a fake macOS password prompt to capture user credentials, which it verifies before proceeding. CrashStealer then accesses and steals data from the macOS Keychain, 14 popular third-party password managers, credentials and cookies from Chromium-based and Firefox browsers, and data from 80 crypto wallet extensions. It also scans user Documents and Downloads folders for files of interest. The stolen data is encrypted with AES-256-GCM and exfiltrated to the attackers. The malware establishes persistence by copying itself to launch at system startup and deletes installation traces to avoid detection. Distribution is controlled via a meeting PIN mechanism, limiting victims to pre-selected targets. The malware was first observed in May 2026 and active in the wild by July 2026. Kaspersky detects it with heuristics under HEUR:Trojan-Downloader.OSX.Agent.gen and HEUR:Trojan-PSW.OSX.Agent.gen.

Potential Impact

CrashStealer compromises macOS systems by stealing a wide range of sensitive information including system Keychain credentials, data from multiple third-party password managers, browser passwords and cookies, crypto wallet extension data, and user documents. This can lead to credential theft, unauthorized access to user accounts, financial theft especially from cryptocurrency wallets, and exposure of private documents. The malware evades macOS built-in defenses by abusing notarization and developer certificates, and uses social engineering to capture passwords. Persistence and anti-forensic measures make detection and removal more difficult.

Defensive Guidance

No official patch or fix is available as this is malware rather than a software vulnerability. Users should avoid downloading software from untrusted sources and verify applications before installation. Sticking to official app stores and verified developers reduces risk. Using reliable security solutions that detect and block malware like CrashStealer is recommended. Users should be cautious of unexpected password prompts and avoid entering credentials unless certain of legitimacy. Keeping credentials in secure password managers not targeted by this malware can reduce impact. Kaspersky security products detect this malware with heuristic signatures. Regular backups and monitoring for unusual system behavior can aid recovery.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.kaspersky.com/blog/crashstealer-werkbit-macos-infostealer/56217/","fetched":true,"fetchedAt":"2026-08-03T14:14:38.099Z","wordCount":1475}
Classification
{"confidence":0.83,"severitySource":"default","classifier":"rss-v2"}

Threat ID: 6a70a24ebf32cb7a34b4637c

Added to database: 08/03/2026, 14:14:38 UTC

Last enriched: 08/03/2026, 14:14:50 UTC

Last updated: 09/17/2026, 09:36:08 UTC

Views: 118

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses