Breaking News
Menu
Advertisement

CrashStealer Malware Bypasses Apple Gatekeeper to Hijack Mac Passwords and Crypto

CrashStealer Malware Bypasses Apple Gatekeeper to Hijack Mac Passwords and Crypto

Mac users often rely on Apple's closed ecosystem for peace of mind, but a new threat is actively shattering that illusion. A sophisticated macOS infostealer named CrashStealer is currently bypassing Apple's built-in Gatekeeper defenses to hijack passwords, crypto wallets, and sensitive documents. If you recently downloaded a videoconferencing tool outside the official Mac App Store, your system might already be compromised.

Security researchers first spotted the development of this malware in May 2026, and it is now operating in the wild alongside another threat known as ClickLock. The attackers use a highly targeted distribution method, directing victims to a fake website that poses as a legitimate platform for a videoconferencing tool called Werkbit. To limit exposure and evade automated scanners, the site requires visitors to enter a special meeting PIN before they can download the software.

Once the "lucky" user enters the PIN, they download the initial malicious payload, named Werkbit Setup. Alarmingly, this installer carries a valid Apple developer certificate and has successfully passed Apple's automated notarization process. This critical failure in the prescan system allows the payload to launch without triggering the usual untrusted software warnings from the macOS Gatekeeper.

How CrashStealer Infiltrates Your System

After launching, Werkbit Setup reaches out to a GitHub repository to retrieve instructions, a tactic that helps the network requests blend in with normal developer traffic. It then connects to the attackers' server, fetches the CrashStealer malware, saves it to a temporary folder, and wipes the setup files. The user never actually receives a videoconferencing app.

Unlike the loader, CrashStealer itself lacks an Apple certificate. To avoid suspicion, it disguises itself as the built-in macOS crash reporting tool, using the exact name, app identifier, and a similar icon to CrashReporter. The malware then executes a precise sequence to compromise the system:

  1. Remove the metadata attributes from the file.
    This ensures the operating system no longer flags the application as an internet download.
  2. Display a highly convincing fake system prompt.
    This tricks the user into entering their macOS password, and it will repeatedly pop up if a typo is made.
  3. Access the built-in Keychain password manager.
    This enables the malware to extract stored account credentials, cryptographic keys, and certificates using the stolen password.
  4. Scan the computer for installed security tools.
    This allows the malware to identify and potentially evade active malware analysis software.
  5. Collect saved data from browsers and third-party apps.
    This ensures the attackers capture cookies, passwords, and crypto wallet data from across the entire system.
  6. Encrypt the stolen data using the AES-256-GCM algorithm.
    This secures the hijacked information into a ZIP file before forwarding it to the attackers' command server.
  7. Establish system persistence by creating a copy of itself.
    This ensures the infostealer launches automatically every time the macOS system boots up.
  8. Delete temporary files and installation traces.
    This makes post-infection detection and forensic analysis significantly harder for security tools.

The Massive Scope of Stolen Data

CrashStealer's hit list is extensive, targeting far more than just the native macOS Keychain. The malware actively steals data from 14 different third-party password managers, specifically targeting 1Password, Bitwarden, LastPass, Dashlane, Keeper, KeePassXC, NordPass, Enpass, and RoboForm. It also sweeps the Documents and Downloads folders for sensitive files.

Web browsers are equally vulnerable. The infostealer collects all credentials and cookies stored in Firefox and Chromium-based browsers, including Chrome, Brave, Edge, Opera, Opera GX, Vivaldi, Chromium, and NAVER Whale. Furthermore, the attackers have a clear financial motive, as CrashStealer targets data from 80 different crypto wallet extensions, including MetaMask, Phantom, Coinbase Wallet, Trust Wallet, Rabby, Exodus, Keplr, and Solflare.

How to Protect Your Mac from Infostealers

The spike in macOS attacks is a clear wake-up call that Apple users must adopt proactive security measures. Follow these steps to secure your device against CrashStealer and similar threats:

  • Research applications thoroughly online before installing them.
    This ensures you avoid downloading disguised malware from fake promotional websites.
  • Download utilities exclusively from the official Mac App Store whenever possible.
    This minimizes the risk of encountering compromised installers that bypass system defenses.
  • Install a reliable security solution on your system.
    This enables real-time blocking of malicious websites and stops unauthorized malware activity. Kaspersky security solutions currently detect this threat as HEUR:Trojan-Downloader.OSX.Agent.gen and HEUR:Trojan-PSW.OSX.Agent.gen.
  • Store all credentials and banking details in a secure, isolated password manager.
    This protects your data even if the system Keychain is compromised. Notably, Kaspersky Password Manager was not listed among the apps targeted by CrashStealer.

The Illusion of Automated Notarization

The most alarming aspect of the CrashStealer campaign is not the malware's data-harvesting capabilities, but how easily its loader bypassed Apple's primary security checkpoints. By successfully passing the macOS notarization process with a valid developer certificate, the attackers exposed a glaring blind spot in automated security prescans. When malicious payloads are hidden behind secondary downloads and GitHub repositories, static analysis tools at the OS level are effectively rendered blind.

This incident highlights a fundamental shift in cybercriminal tactics targeting Apple users. Attackers are moving away from brute-force exploits and instead weaponizing trust - using targeted PIN codes to evade security researchers and mimicking native tools like CrashReporter to avoid raising user suspicion. As macOS continues to gain market share in enterprise environments, the reliance on Apple's walled garden is no longer a sufficient defense strategy.

Did you like this article?
Advertisement

Popular Searches