{*}
Add news
March 2010 April 2010 May 2010 June 2010 July 2010
August 2010
September 2010 October 2010 November 2010 December 2010 January 2011 February 2011 March 2011 April 2011 May 2011 June 2011 July 2011 August 2011 September 2011 October 2011 November 2011 December 2011 January 2012 February 2012 March 2012 April 2012 May 2012 June 2012 July 2012 August 2012 September 2012 October 2012 November 2012 December 2012 January 2013 February 2013 March 2013 April 2013 May 2013 June 2013 July 2013 August 2013 September 2013 October 2013 November 2013 December 2013 January 2014 February 2014 March 2014 April 2014 May 2014 June 2014 July 2014 August 2014 September 2014 October 2014 November 2014 December 2014 January 2015 February 2015 March 2015 April 2015 May 2015 June 2015 July 2015 August 2015 September 2015 October 2015 November 2015 December 2015 January 2016 February 2016 March 2016 April 2016 May 2016 June 2016 July 2016 August 2016 September 2016 October 2016 November 2016 December 2016 January 2017 February 2017 March 2017 April 2017 May 2017 June 2017 July 2017 August 2017 September 2017 October 2017 November 2017 December 2017 January 2018 February 2018 March 2018 April 2018 May 2018 June 2018 July 2018 August 2018 September 2018 October 2018 November 2018 December 2018 January 2019 February 2019 March 2019 April 2019 May 2019 June 2019 July 2019 August 2019 September 2019 October 2019 November 2019 December 2019 January 2020 February 2020 March 2020 April 2020 May 2020 June 2020 July 2020 August 2020 September 2020 October 2020 November 2020 December 2020 January 2021 February 2021 March 2021 April 2021 May 2021 June 2021 July 2021 August 2021 September 2021 October 2021 November 2021 December 2021 January 2022 February 2022 March 2022 April 2022 May 2022 June 2022 July 2022 August 2022 September 2022 October 2022 November 2022 December 2022 January 2023 February 2023 March 2023 April 2023 May 2023 June 2023 July 2023 August 2023 September 2023 October 2023 November 2023 December 2023 January 2024 February 2024 March 2024 April 2024 May 2024 June 2024 July 2024 August 2024 September 2024 October 2024 November 2024 December 2024 January 2025 February 2025 March 2025 April 2025 May 2025 June 2025 July 2025 August 2025 September 2025 October 2025 November 2025 December 2025 January 2026 February 2026 March 2026 April 2026 May 2026 June 2026 July 2026
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21
22
23
24
25
26
27
28
29
30
31
News Every Day |

CrashStealer Mac malware steals passwords and wallets

A polished installer can make risky software feel routine. You see a familiar Mac window, follow the directions and enter your password when asked. By then, the app may already be working against you.

Security researchers at Jamf Threat Labs have uncovered CrashStealer, a new Mac information stealer that impersonates Apple's crash-reporting software. Jamf first tracked the malware in May 2026 while it appeared to be under development. By early July, researchers detected it in active attacks.

Free live CyberGuy class: Sick of Spam? Join us on July 22.

Join us this Wednesday, July 22, at 1 PM ET for a free CyberGuy Live class that will help you cut down on robocalls, spam texts, junk email and other unwanted messages. Kurt "CyberGuy" Knutsson will walk you step by step through simple ways to filter spam, clean up your inbox and recognize the messages that could put your personal information at risk. No technical experience is needed. You’ll also receive our spam-stopping checklist, and every registrant will get a link to the class recording afterward.

Reserve your free spot today at CyberGuyLive.com.

REDHOOK ANDROID MALWARE CAN QUIETLY HIJACK YOUR PHONE

CrashStealer targets information many people rely on every day. It searches for browser credentials, password-manager data and cryptocurrency wallet information. The malware can copy the Mac login Keychain as well. The malware stands out because its developers wrote it in native C++. Many common Mac stealers rely on AppleScript or simpler software wrappers.

CrashStealer also encrypts the files it collects before sending them to an attacker-controlled server. Meanwhile, anti-debugging features make the malware harder for researchers to examine. However, the first app a victim sees isn’t called CrashStealer. The attack begins with a disk image branded as "Werkbit Setup."

The Werkbit Setup disk image contains a polished installer. Its directions tell the user to right-click the app and choose Open. That action often appears in instructions for software that needs to get around a Mac security warning. In this case, the installer already carried a valid Apple Developer ID and a notarization ticket. Therefore, it could clear Gatekeeper on its first launch. Jamf also found that the disk image itself had been signed, which researchers called unusual for malicious Mac delivery.

The website that distributed Werkbit Setup required a meeting PIN. That setup may have helped the attackers limit access to people who received the correct code. It also made the download feel more exclusive and potentially more believable.

Once opened, Werkbit Setup contacted GitHub for an initial command. It then downloaded a script from the attackers' infrastructure. Next, the script installed a second disk image named CrashReporter.dmg in a hidden temporary folder. The payload used the name CrashReporter and the bundle identifier com.apple.crashreporter. Those details were chosen to resemble an Apple system component. The malware then launched quietly in the background.

Apple uses Gatekeeper alongside Developer ID signing to reduce the risk from downloaded software. Its notarization process checks an app for known malicious content when developers submit it. Gatekeeper can also check whether Apple has revoked the signing certificate. Still, a notarized label should never replace your judgment about where an app came from.

A harmful app can slip through before researchers or Apple identify its behavior. Attackers can also use a trusted first-stage installer to retrieve a different payload after launch. Jamf reported the Developer Team ID connected to Werkbit Setup to Apple after confirming that it had distributed malicious software. The report did not say how many people had been infected.

After CrashStealer launches, it displays a password prompt designed to resemble a legitimate macOS authorization request. The malware checks the password locally with a built-in Mac directory service command.

If the password is wrong, the prompt returns. If it is correct, CrashStealer stores an obfuscated copy and uses the credential to unlock the login Keychain.

The malware can then copy the Keychain database into its collection folder. That makes the prompt one of the most important warning signs. A password request can look convincing, yet the timing may feel wrong. An online meeting installer should not need your Mac password to display a call or download ordinary content.

CrashStealer searches broadly across the Mac. Jamf found code and activity tied to Chromium-based browsers, Safari data and Firefox credential files. The malware also checked wallet extensions such as MetaMask and Phantom. In addition, it targeted password managers that included 1Password, Bitwarden, LastPass and Dashlane. Jamf observed roughly 80 cryptocurrency wallet extensions and 14 password managers in the target list.

A separate file-search tool scans locations such as Documents and Downloads. However, it skips many large installers, apps and media files. That filtering suggests the thieves want compact files that may contain credentials or financial records. Other personal documents may also appeal to the attackers.

CrashStealer stores stolen material inside hidden folders under the user's home directory. It encrypts each collected item with AES-256-GCM. Then it packages groups of encrypted files into hidden ZIP archives before uploading them. Encryption helps the attackers conceal the contents of the stolen files while they sit on the Mac. It also means a leftover archive can confirm that collection occurred even when an investigator cannot read the data inside it.

The malware then copies itself into the Mac's Library cache folder. It creates a LaunchAgent that starts the copied app when the user logs in. The LaunchAgent uses an Apple-like name, which can make the entry blend in during a quick inspection.

HALLUSQUATTING AI ATTACK COULD HIJACK YOUR COMPUTER

You may have encountered this campaign after downloading Werkbit Setup. The risk rises if the website requires a meeting PIN. An unexpected CrashReporter password prompt is another red flag. Be more suspicious when the prompt appears right after installing unrelated software or joining an online meeting.

Also, watch for an unfamiliar app asking for Full Disk Access or permission to reach Documents and Downloads. CrashStealer's configuration included permission messages designed to make broad file access sound necessary for "system administration." Security teams can also look for the hidden CrashReporter locations and LaunchAgent described in Jamf's technical report. However, most home users should avoid digging through system folders unless they know exactly what they are changing.

A few careful habits can help you spot a suspicious Mac installer before it gets access to your passwords and personal files.

Use the Mac App Store when possible. Otherwise, type the developer's official website address yourself. Avoid downloading software from a meeting link, private message or unexpected pop-up unless you can independently confirm the source.

Be wary when an installer tells you to right-click and choose Open or use the Open Anyway button. Apple recommends overriding a security warning only when you trust the app's source. You should also confirm that nobody altered the download.

Look at which app triggered the prompt and why it needs authorization. Cancel the request when the reason does not match what you are doing. Then close the app and verify the download with the company through a separate channel.

Open the Apple menu > System Settings > Privacy & Security. Review Full Disk Access, Files & Folders and Accessibility for apps you do not recognize. Turn off access for anything suspicious.

Next, open System Settings > General > Login Items & Extensions. Review the apps listed under Open at Login and Allow in the Background. Remove or disable unfamiliar entries.

You can also check System Settings > General > Device Management for profiles you do not recognize. This option may appear only when a profile is installed. Do not remove a work or school profile without contacting the administrator first.

Open the Apple menu > System Settings > General > Software Update . Install available updates promptly because they include current security protections.

A trusted antivirus program can help detect known malicious files, suspicious persistence and harmful network behavior. Keep real-time protection enabled and allow the software to update automatically. Jamf says threat-prevention tools can help block and report similar Mac threats. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com

Disconnect the Mac from the internet. Do not enter another password on that computer. Run a full scan with trusted security software. You should also contact Apple Support or your workplace IT team.

Next, use a clean device to change the password for your Apple Account, primary email account and password manager. Change passwords for banking, shopping and other sensitive accounts that were saved on the affected Mac. Enable two-factor authentication (2FA) where available and sign out of devices or active sessions you do not recognize.

After the Mac has been cleaned, change its login password because CrashStealer may have captured and validated that credential.

If you use cryptocurrency wallets on the affected Mac, treat their private keys and recovery phrases as exposed. Move remaining funds to newly created wallets from a clean device. Never reuse the old recovery phrase.

If security software cannot confirm that CrashStealer has been fully removed, contact Apple Support or a qualified technician about erasing the Mac and reinstalling macOS. Restore personal files carefully from a backup created before the infection, when possible.

FBI HELPS TAKE DOWN AI PHISHING RING

CrashStealer shows how attackers can wrap harmful software in a convincing Mac experience. The signed Werkbit installer gave the campaign a layer of credibility. Then the fake crash reporter used a familiar password prompt to reach valuable data on the computer. Your best defense begins before the password prompt appears. Verify the source of every installer and stop when the instructions ask you to bypass a warning. Strong antivirus protection and current macOS updates add another barrier.

Would Apple notarization earn your trust, or would you still question a polished Mac installer? Let us know by writing to us at Cyberguy.com

Sign up for my FREE CyberGuy Report

Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.

For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com - trusted by millions who watch CyberGuy on TV daily.

Plus, you'll get instant access to my Ultimate Scam Survival Guide free when you join.

Copyright 2026 CyberGuy.com. All rights reserved.

Ria.city






Read also

Forget the mojito: Experts say Ernest Hemingway's signature drink was likely something else

Treasury hails success of anti-fraud process that flagged and prevented $99 million in payments to dead people

Startling mystery revealed in centuries-old royal tombs at powerful queen's monastery

News, articles, comments, with a minute-by-minute update, now on Today24.pro

Today24.pro — latest news 24/7. You can add your news instantly now — here




Sports today


Новости тенниса


Спорт в России и мире


All sports news today





Sports in Russia today


Новости России


Russian.city



Губернаторы России









Путин в России и мире







Персональные новости
Russian.city





Friends of Today24

Музыкальные новости

Персональные новости