bleeping-computer · Crawled Jul 13, 2026

New CrashStealer malware poses as Apple crash reporting tool

4 IoCs
Read original article ↗

AI Summary

A new macOS information-stealing malware named CrashStealer impersonates Apple's crash reporting tool to evade detection and steal sensitive data. It uses a signed and notarized installer to bypass macOS Gatekeeper, tricks users with a fake password prompt to access Keychain data, and targets browser credentials, crypto wallets, and password managers. The malware encrypts stolen data with AES-256-GCM before exfiltration, indicating a sophisticated and stealthy operation.

AI-extracted · verify before operational use

Indicators of Compromise 4 extracted

Type Value Detail
Domain werkbit[.]com Details →
Filename CrashReporter.app Details →
Filename com.apple.crashreporter.helper Details →
Package Werkbit Setup Details →