Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Single CAR T Injection Eases Multiple Sclerosis Symptoms in Small Trial

    September 15, 2026

    AI ‘Actor’ Tilly Norwood Told Me That ‘All Lives Matter’

    September 15, 2026

    Roundtables: Could AI really kill us all?

    September 15, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Single CAR T Injection Eases Multiple Sclerosis Symptoms in Small Trial
    • AI ‘Actor’ Tilly Norwood Told Me That ‘All Lives Matter’
    • Roundtables: Could AI really kill us all?
    • How Elon Musk and Tesla Forged a New EV Path
    • The Download: AI doomers, whistleblowing agents, and de-aged livers
    • Inside the Inference Hardware Revolution Of 2026
    • What must happen for AI’s trillion-dollar gamble to pay off
    • When AI agents cheated at math, other AI agents blew the whistle on them
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»New macOS malware steals passwords by posing as Apple’s crash-reporting tool
    Cybersecurity

    New macOS malware steals passwords by posing as Apple’s crash-reporting tool

    kirklandc008@gmail.comBy kirklandc008@gmail.comJuly 14, 2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Hackers hijacked CPUID downloads, served STX RAT to victims
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Jamf Threat Labs has uncovered a new macOS infostealer named CrashStealer that disguises itself as Apple’s crash-reporting tool to steal passwords, Keychain data, and cryptocurrency wallets.

    The malware was first spotted in May while it was still under development. By early July, Jamf was seeing in-the-wild detections, indicating it had moved into active use.

    “Unlike much of the commodity stealer activity on macOS, which is built on AppleScript droppers or thin Objective-C wrappers, CrashStealer is implemented in native C++ around an internal class the authors named MacOSData,” the researchers wrote.

    “It validates the victim’s login password locally before harvesting, collects broadly across browsers, cryptocurrency wallets, password managers and the Keychain, encrypts what it collects with AES-GCM before exfiltrating over libcurl, and persists by copying and re-signing itself.”

    Signed installer starts the attack

    The attack starts with a disk image named “Werkbit Setup.” When opened, it mounts a volume containing a single application, Werkbit.app. Its executable, named veltod, launches the next stage of the infection.

    Werkbit Setup (Source: Jamf)

    The dropper is a universal binary signed with the Developer ID “Emil Grigorov (WWB7JA7AQV)” and carries a stapled notarization ticket. This lets it pass Gatekeeper, macOS’s built-in protection against untrusted software, on first launch.

    “Notably, the disk image itself is signed as well, not just the application inside it, which is uncommon in malicious DMG delivery where the container is typically left unsigned,” they added.

    Jamf reported the Developer Team ID behind the signature to Apple after confirming its use in the campaign.

    The installer was hosted on werkbit[.]io, a domain registered in late June, close to the build date of the dropper analyzed. Downloading it requires a meeting PIN, limiting access to people who already have the code. The report links the activity to other domains and shared infrastructure, indicating CrashStealer is one piece of a broader operation.

    GitHub delivers the next stage

    After launch, the veltod executable contacts a GitHub repository and downloads a file that supplies a command to fetch a script from a separate server. The script decodes its commands at runtime before downloading the next stage.

    The script downloads CrashReporter.dmg, mounts it, and copies the application bundle into a hidden folder before deleting the disk image. The payload uses the icon, display name, and bundle identifier of Apple’s crash-reporting component to resemble a system utility.

    Malware targets passwords, browsers, and cryptocurrency wallets

    CrashStealer displays a password prompt designed to look like a macOS system dialog. It checks the password locally with the dscl command, a built-in macOS tool used to verify user credentials, and asks again if the password is wrong.

    After receiving the correct password, the infostealer unlocks the login Keychain and copies it into a hidden staging folder. It also collects data from Documents, Downloads, and other user folders, skipping executables, installers, disk images, and bulky archive or media files to limit the amount of data collected.

    It also targets Chromium browser profiles, Firefox login data, about 80 cryptocurrency wallet extensions such as MetaMask, Phantom, Coinbase Wallet, Trust Wallet, and Exodus, as well as 14 password managers, among them 1Password, Bitwarden, LastPass, Dashlane, and Keeper.

    Collected files are encrypted one by one with AES-256-GCM before being stored, then packed into hidden ZIP archives and uploaded to a command-and-control server with libcurl, a networking library commonly used to transfer data over HTTP and HTTPS.

    Although CrashStealer targets the same types of data as other macOS infostealers, its native C++ implementation and client-side encryption set it apart, leading the researchers to classify it as a separate malware family.

    Persistence and anti-analysis

    CrashStealer copies itself to another location and applies a new ad hoc signature to the copied binary. It installs the copy as a LaunchAgent named “com.apple.crashreporter.helper,” allowing it to run each time the user logs in.

    The malware also includes code designed to slow analysis, with flattened control flow, strings decrypted only at runtime, and debugger checks placed at more than one point during startup.

    Jamf’s report provides indicators of compromise, file names and hashes, delivery infrastructure details, and filesystem artifacts left behind after an infection.

    Apples crashreporting macOS malware Passwords Posing steals tool
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Clearview AI Is Testing an AI Tool That Would Let Cops Unearth Your Life Online

    September 10, 2026

    This Is Flock’s AI Search Tool for Cops

    September 3, 2026

    He Scraped All of Their Art for AI. Now He’s Collaborating on a Tool to Help Them

    August 28, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    The best VPN routers of 2026: Expert tested and reviewed

    June 14, 20263 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • Single CAR T Injection Eases Multiple Sclerosis Symptoms in Small Trial
    • AI ‘Actor’ Tilly Norwood Told Me That ‘All Lives Matter’
    • Roundtables: Could AI really kill us all?
    • How Elon Musk and Tesla Forged a New EV Path
    • The Download: AI doomers, whistleblowing agents, and de-aged livers

    Single CAR T Injection Eases Multiple Sclerosis Symptoms in Small Trial

    September 15, 2026

    AI ‘Actor’ Tilly Norwood Told Me That ‘All Lives Matter’

    September 15, 2026

    Roundtables: Could AI really kill us all?

    September 15, 2026

    How Elon Musk and Tesla Forged a New EV Path

    September 15, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.