Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Here’s why AI agents lie and cheat to reach their goals

    August 3, 2026

    The Magnetophon and the Birth of the Laugh Track

    August 2, 2026

    Page Not Found | WIRED

    August 2, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Here’s why AI agents lie and cheat to reach their goals
    • The Magnetophon and the Birth of the Laugh Track
    • Page Not Found | WIRED
    • This Week’s Awesome Tech Stories From Around the Web (Through August 1)
    • Nobody Knows if OpenAI’s and Anthropic’s AI Hacking Sprees Are Illegal
    • The Man Who Understood Risk: Robert N. Charette retires.
    • 7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran
    • Gemini Robotics 2 Brings Google’s AI Into the Physical World
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»New macOS malware steals passwords by posing as Apple’s crash-reporting tool
    Cybersecurity

    New macOS malware steals passwords by posing as Apple’s crash-reporting tool

    kirklandc008@gmail.comBy kirklandc008@gmail.comJuly 14, 2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Hackers hijacked CPUID downloads, served STX RAT to victims
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Jamf Threat Labs has uncovered a new macOS infostealer named CrashStealer that disguises itself as Apple’s crash-reporting tool to steal passwords, Keychain data, and cryptocurrency wallets.

    The malware was first spotted in May while it was still under development. By early July, Jamf was seeing in-the-wild detections, indicating it had moved into active use.

    “Unlike much of the commodity stealer activity on macOS, which is built on AppleScript droppers or thin Objective-C wrappers, CrashStealer is implemented in native C++ around an internal class the authors named MacOSData,” the researchers wrote.

    “It validates the victim’s login password locally before harvesting, collects broadly across browsers, cryptocurrency wallets, password managers and the Keychain, encrypts what it collects with AES-GCM before exfiltrating over libcurl, and persists by copying and re-signing itself.”

    Signed installer starts the attack

    The attack starts with a disk image named “Werkbit Setup.” When opened, it mounts a volume containing a single application, Werkbit.app. Its executable, named veltod, launches the next stage of the infection.

    Werkbit Setup (Source: Jamf)

    The dropper is a universal binary signed with the Developer ID “Emil Grigorov (WWB7JA7AQV)” and carries a stapled notarization ticket. This lets it pass Gatekeeper, macOS’s built-in protection against untrusted software, on first launch.

    “Notably, the disk image itself is signed as well, not just the application inside it, which is uncommon in malicious DMG delivery where the container is typically left unsigned,” they added.

    Jamf reported the Developer Team ID behind the signature to Apple after confirming its use in the campaign.

    The installer was hosted on werkbit[.]io, a domain registered in late June, close to the build date of the dropper analyzed. Downloading it requires a meeting PIN, limiting access to people who already have the code. The report links the activity to other domains and shared infrastructure, indicating CrashStealer is one piece of a broader operation.

    GitHub delivers the next stage

    After launch, the veltod executable contacts a GitHub repository and downloads a file that supplies a command to fetch a script from a separate server. The script decodes its commands at runtime before downloading the next stage.

    The script downloads CrashReporter.dmg, mounts it, and copies the application bundle into a hidden folder before deleting the disk image. The payload uses the icon, display name, and bundle identifier of Apple’s crash-reporting component to resemble a system utility.

    Malware targets passwords, browsers, and cryptocurrency wallets

    CrashStealer displays a password prompt designed to look like a macOS system dialog. It checks the password locally with the dscl command, a built-in macOS tool used to verify user credentials, and asks again if the password is wrong.

    After receiving the correct password, the infostealer unlocks the login Keychain and copies it into a hidden staging folder. It also collects data from Documents, Downloads, and other user folders, skipping executables, installers, disk images, and bulky archive or media files to limit the amount of data collected.

    It also targets Chromium browser profiles, Firefox login data, about 80 cryptocurrency wallet extensions such as MetaMask, Phantom, Coinbase Wallet, Trust Wallet, and Exodus, as well as 14 password managers, among them 1Password, Bitwarden, LastPass, Dashlane, and Keeper.

    Collected files are encrypted one by one with AES-256-GCM before being stored, then packed into hidden ZIP archives and uploaded to a command-and-control server with libcurl, a networking library commonly used to transfer data over HTTP and HTTPS.

    Although CrashStealer targets the same types of data as other macOS infostealers, its native C++ implementation and client-side encryption set it apart, leading the researchers to classify it as a separate malware family.

    Persistence and anti-analysis

    CrashStealer copies itself to another location and applies a new ad hoc signature to the copied binary. It installs the copy as a LaunchAgent named “com.apple.crashreporter.helper,” allowing it to run each time the user logs in.

    The malware also includes code designed to slow analysis, with flattened control flow, strings decrypted only at runtime, and debugger checks placed at more than one point during startup.

    Jamf’s report provides indicators of compromise, file names and hashes, delivery infrastructure details, and filesystem artifacts left behind after an infection.

    Apples crashreporting macOS malware Passwords Posing steals tool
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026

    The 3 types of people who will excel in the AI agent era, according to tech leaders

    July 26, 2026

    Steam forum ClickFix attacks infect gamers with XMRig cryptominers

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • Here’s why AI agents lie and cheat to reach their goals
    • The Magnetophon and the Birth of the Laugh Track
    • Page Not Found | WIRED
    • This Week’s Awesome Tech Stories From Around the Web (Through August 1)
    • Nobody Knows if OpenAI’s and Anthropic’s AI Hacking Sprees Are Illegal

    Here’s why AI agents lie and cheat to reach their goals

    August 3, 2026

    The Magnetophon and the Birth of the Laugh Track

    August 2, 2026

    Page Not Found | WIRED

    August 2, 2026

    This Week’s Awesome Tech Stories From Around the Web (Through August 1)

    August 1, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.