{"id":56217,"date":"2026-08-03T10:01:21","date_gmt":"2026-08-03T14:01:21","guid":{"rendered":"https:\/\/www.kaspersky.com\/blog\/?p=56217"},"modified":"2026-08-03T10:07:40","modified_gmt":"2026-08-03T14:07:40","slug":"crashstealer-werkbit-macos-infostealer","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com\/blog\/crashstealer-werkbit-macos-infostealer\/56217\/","title":{"rendered":"CrashStealer: notarized malware for macOS"},"content":{"rendered":"<p>Mac users have historically trusted their operating system to keep them safe. That peace of mind mostly comes from Apple\u2019s strict control over its ecosystem, and the fact that macOS has historically faced fewer mass attacks than Windows. However, that doesn\u2019t mean Macs are invulnerable: threats do exist, and new ones emerge all the time. Over just the past few weeks, security researchers have published reports on at least two new campaigns that target Apple devices.<\/p>\n<p>The malware used in one of the campaigns has been dubbed <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-crashstealer-malware-poses-as-apple-crash-reporting-tool\/\" target=\"_blank\" rel=\"noopener nofollow\">CrashStealer<\/a>, while the other is known as <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-clicklock-macos-malware-traps-users-into-revealing-login-password\/\" target=\"_blank\" rel=\"noopener nofollow\">ClickLock<\/a>. Both rely on different tricks to force users into entering their Mac password, which attackers then use to steal account credentials, crypto assets, documents, and much more. In today\u2019s post, we take a close look at how CrashStealer operates\u00a0\u2014 and how to avoid falling victim to it.<\/p>\n<h2>A videoconferencing app with CrashStealer inside<\/h2>\n<p>It was back in May 2026 that researchers spotted the first signs this malware was being developed, and by early July, they caught it operating in the wild. The malware earned its name because of its core mechanism: it disguises itself as the macOS built-in crash reporting tool (CrashReporter) while functioning as an infostealer designed to hijack sensitive data.<\/p>\n<p>Researchers managed to trace one of the websites users visited to download the malware. The site poses as a legitimate platform for distributing the video conferencing tool Werkbit.<\/p>\n<div id=\"attachment_56221\" style=\"width: 1282px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2026\/08\/03095133\/crashstealer-werkbit-macos-infostealer-1.jpg\"><img decoding=\"async\" aria-describedby=\"caption-attachment-56221\" class=\"wp-image-56221 size-full\" title=\"A website that distributes CrashStealer under the guise of the Werkbit app\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2026\/08\/03095133\/crashstealer-werkbit-macos-infostealer-1.jpg\" alt=\"A website that distributes CrashStealer under the guise of the Werkbit app \" width=\"1272\" height=\"924\"><\/a><p id=\"caption-attachment-56221\" class=\"wp-caption-text\">According to researchers, this is the site victims used to download Werkbit, which secretly contained the CrashStealer malware loader. <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-crashstealer-malware-poses-as-apple-crash-reporting-tool\/\" target=\"_blank\" rel=\"nofollow noopener\"> Source <\/a><\/p><\/div>\n<p>However, you can\u2019t just visit the site and download the software. Before downloading, visitors are asked to enter a special meeting PIN. This setup likely allows the attackers to limit the distribution scope by targeting only specific, pre-selected victims. Exactly how the cybercriminals choose their targets and deliver the PIN remains unknown.<\/p>\n<p>The \u201clucky\u201d users with a code end up installing the initial malicious payload \u2014 named Werkbit Setup. Interestingly, it carries a valid Apple developer certificate and has successfully passed Apple\u2019s notarization process\u00a0\u2014 meaning it cleared the automated prescan for malicious code. As a result, the attackers manage to bypass the operating system\u2019s built-in Gatekeeper defense. This allows the payload to launch without triggering the usual untrusted software warnings.<\/p>\n<div id=\"attachment_56222\" style=\"width: 1158px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2026\/08\/03095359\/crashstealer-werkbit-macos-infostealer-2.jpg\"><img decoding=\"async\" aria-describedby=\"caption-attachment-56222\" class=\"wp-image-56222 size-full\" title=\"Signed and notarized Werkbit Setup installer\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2026\/08\/03095359\/crashstealer-werkbit-macos-infostealer-2.jpg\" alt=\"Signed and notarized Werkbit Setup installer\" width=\"1148\" height=\"920\"><\/a><p id=\"caption-attachment-56222\" class=\"wp-caption-text\">The Werkbit Setup installer is signed with a valid Apple developer certificate and has passed notarization. <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-crashstealer-malware-poses-as-apple-crash-reporting-tool\/\" target=\"_blank\" rel=\"nofollow noopener\"> Source <\/a><\/p><\/div>\n<p>Once launched, Werkbit Setup first reaches out to GitHub. Researchers believe using this popular platform helps attackers blend in by making these initial network requests look far less suspicious to security tools. After retrieving instructions from a GitHub repository, the program connects directly to the attackers\u2019 server to fetch CrashStealer itself.<\/p>\n<p>The loader then saves the malware to a temporary macOS folder, launches it, and wipes most of the intermediate setup files. As a result, a fully functional infostealer is up and running within seconds of Werkbit Setup starting. By the way, the user never gets any videoconferencing app.<\/p>\n<h2>How CrashStealer works<\/h2>\n<p>Unlike the Werkbit Setup loader, the CrashStealer malware itself isn\u2019t signed with an Apple developer certificate. To keep users from suspecting anything, the malware disguises itself as the built-in macOS crash reporting tool, CrashReporter, by using the exact same name, app identifier, and a similar icon.<\/p>\n<p>Once launched, CrashStealer completes a sequence of steps to gain access to sensitive data, establish persistence in the system, and cover its tracks:<\/p>\n<ol>\n<li>Remove metadata \u2014 including the attribute that flags the app as an internet download.<\/li>\n<li>Display a fake system prompt asking for the user\u2019s macOS password.<\/li>\n<li>Use the previously captured credentials to gain access to Keychain, the built-in macOS password manager.<\/li>\n<li>Check the computer for installed security tools and malware analysis software.<\/li>\n<li>Collect saved browser passwords, cookies, Keychain contents, and data from other password managers and crypto wallets.<\/li>\n<li>Encrypt the data it stole and prepare it for forwarding to the attackers\u2019 server.<\/li>\n<li>Create a copy of itself and establish persistence to launch automatically every time macOS boots.<\/li>\n<li>Delete temporary files and other installation traces to make detection much harder.<\/li>\n<\/ol>\n<p>Step two deserves a closer look. The password prompt that the user sees looks extremely convincing. What\u2019s more, the malware immediately verifies whether the credentials are correct: if you make a typo and enter an invalid password, CrashStealer will pop the window right back up to ask you again.<\/p>\n<div id=\"attachment_56223\" style=\"width: 658px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2026\/08\/03095519\/crashstealer-werkbit-macos-infostealer-3.jpg\"><img decoding=\"async\" aria-describedby=\"caption-attachment-56223\" class=\"wp-image-56223 size-full\" title=\"Fake macOS password prompt\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2026\/08\/03095519\/crashstealer-werkbit-macos-infostealer-3.jpg\" alt=\"Fake macOS password prompt \" width=\"648\" height=\"640\"><\/a><p id=\"caption-attachment-56223\" class=\"wp-caption-text\">Once launched, CrashStealer displays a pop-up that mimics the standard macOS password request. <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-crashstealer-malware-poses-as-apple-crash-reporting-tool\/\" target=\"_blank\" rel=\"nofollow noopener\"> Source <\/a><\/p><\/div>\n<h2>What data is CrashStealer after?<\/h2>\n<p>CrashStealer\u2019s hit list is massive. First and foremost, its operators target Keychain: the built-in macOS password manager where the system stores account credentials, cryptographic keys, certificates, tokens, and more.<\/p>\n<p>Users of third-party password managers aren\u2019t safe either: the malware steals data from 14 of these services, including 1Password, Bitwarden, LastPass, Dashlane, Keeper, KeePassXC, NordPass, Enpass, and RoboForm.<\/p>\n<p>In addition, the malware collects all credentials and cookies stored in Chromium-based browsers\u00a0\u2014 Chrome, Brave, Edge, Opera, Opera GX, Vivaldi, Chromium, and NAVER Whale\u00a0\u2014 as well as Firefox. The attackers clearly have a strong interest in crypto assets: CrashStealer specifically targets data from 80 different crypto wallet extensions, including MetaMask, Phantom, Coinbase Wallet, Trust Wallet, Rabby, Exodus, Keplr, and Solflare.<\/p>\n<p>Finally, the malware scans the Documents and Downloads folders to pick files that might be of interest to the cybercriminals. CrashStealer encrypts all the stolen data with the AES-256-GCM algorithm, ZIP\u2019s it up, and sends it to the attackers\u2019 server.<\/p>\n<h2>How to protect your device<\/h2>\n<p>The spike in attacks on macOS is a clear wake-up call: Apple users need to get proactive about their security. We recommend:<\/p>\n<ul>\n<li>Researching apps online before installing them<\/li>\n<li>Sticking to utilities from official app stores whenever possible<\/li>\n<li>Using a <strong><a href=\"https:\/\/www.kaspersky.com\/mac-antivirus?icid=gl_kdailyplacehold_acq_ona_smm__onl_b2c_kdaily_wpplaceholder_sm-team___kism____2b785c292935c4a3\" target=\"_blank\" rel=\"noopener nofollow\">reliable security solution<\/a><\/strong>\u00a0that blocks malicious websites and stops malware activity on your device<\/li>\n<li>Keeping all your credentials and banking details in <a href=\"https:\/\/www.kaspersky.com\/password-manager?icid=gl_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____kpm___\" target=\"_blank\" rel=\"noopener nofollow\">a secure password manager<\/a>. One option is <a href=\"https:\/\/www.kaspersky.com\/password-manager?icid=gl_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____kpm___\" target=\"_blank\" rel=\"noopener nofollow\">Kaspersky Password Manager<\/a>\u2014 which, notably, wasn\u2019t listed among the apps targeted by CrashStealer<\/li>\n<\/ul>\n<p><strong><a href=\"https:\/\/www.kaspersky.com\/home-security?icid=gl_kdailyplacehold_acq_ona_smm__onl_b2c_blo_lnk_sm-team______\" target=\"_blank\" rel=\"noopener nofollow\">Kaspersky security solutions<\/a><\/strong>\u00a0detect the malware described in this post and assigns to it the verdicts <em>HEUR:Trojan-Downloader.OSX.Agent.gen<\/em> and <em>HEUR:Trojan-PSW.OSX.Agent.gen.<\/em><\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"premium-generic\"><input type=\"hidden\" class=\"placeholder_for_banner\" data-cat_id=\"premium-generic\" value=\"52942\">\n","protected":false},"excerpt":{"rendered":"<p>CrashStealer is a macOS infostealer disguised as a videoconferencing app. It abuses Apple&#8217;s own trusted mechanisms to sneak onto your computer unnoticed.<\/p>\n","protected":false},"author":2726,"featured_media":56218,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2683],"tags":[14,2640,4657,1946,405,187,97,513,3244,422],"class_list":{"0":"post-56217","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threats","8":"tag-apple","9":"tag-cryptocurrencies","10":"tag-infostealers","11":"tag-macos","12":"tag-password-manager","13":"tag-passwords","14":"tag-security-2","15":"tag-social-engineering","16":"tag-stealers","17":"tag-threats"},"hreflang":[{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/crashstealer-werkbit-macos-infostealer\/56217\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/crashstealer-werkbit-macos-infostealer\/30947\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/crashstealer-werkbit-macos-infostealer\/25975\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/crashstealer-werkbit-macos-infostealer\/30777\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/crashstealer-werkbit-macos-infostealer\/42416\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/crashstealer-werkbit-macos-infostealer\/30910\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/crashstealer-werkbit-macos-infostealer\/36441\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/crashstealer-werkbit-macos-infostealer\/36355\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com\/blog\/tag\/macos\/","name":"macOS"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/56217","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/2726"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=56217"}],"version-history":[{"count":4,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/56217\/revisions"}],"predecessor-version":[{"id":56225,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/56217\/revisions\/56225"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/56218"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=56217"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=56217"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=56217"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}