macOS infostealer poses as Apple crash reporter
🛡️ A new macOS infostealer named CrashStealer impersonates Apple's crash-reporting component to trick users into installing a password-stealing payload. Delivered via a signed, notarized disk image called "Werkbit Setup," the dropper bypasses Gatekeeper and fetches a downloader that installs the C++-based stealer. Once active, it prompts for system credentials and exfiltrates browser-stored logins, crypto wallet access and keychain data, using client-side encryption and anti-analysis techniques.
