hacker-news · Crawled Jul 13, 2026

CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks

7 IoCs
Read original article ↗

AI Summary

CrashStealer is a newly identified macOS information stealer written in native C++ that evades Gatekeeper by using a signed and Apple-notarized dropper. It harvests credentials from browsers, cryptocurrency wallets, password managers, and keychain data, encrypts the stolen data using AES-GCM, and exfiltrates it to an attacker-controlled server. The malware employs analysis resistance techniques such as control-flow flattening and anti-debugging, and uses a multi-stage delivery chain involving a GitHub-hosted payload.

AI-extracted · verify before operational use

Indicators of Compromise 7 extracted

Type Value Detail
Domain werkbit[[.]]io Details →
IP 179[.]43[.]166[.]242 Details →
Domain github[.]com/mgothiclove Details →
Filename sys.cache Details →
Filename CrashReporter.dmg Details →
Filename Werkbit.app Details →
GitHub Repo mgothiclove Details →