<- ALL CYBER NEWS

Notable

CrashStealer, macOS, infostealer, Gatekeeper, notarization, keychain, crypto

A Fake Apple Crash Reporter Is Stealing Mac Keychains, and It Passed Apple's Own Checks

A new macOS infostealer called CrashStealer disguises itself as Apple's crash-reporting tool to steal credentials, keychain data, and crypto wallets, using a notarized dropper that slips past Gatekeeper. The Mac-is-safe assumption keeps eroding.

A new macOS information stealer called CrashStealer is disguising itself as Apple's crash-reporting tool to harvest credentials, keychain data, and cryptocurrency wallets, and it uses a notarized dropper to pass Apple's Gatekeeper checks, as reported by The Hacker News and BleepingComputer.

The notarization detail is the important one. Gatekeeper is the macOS feature meant to block software Apple has not vetted, and notarization is the stamp that says a program cleared an automated Apple review. CrashStealer carrying that stamp means the usual reasoning, that a signed and notarized app is therefore safe, does not hold here.

The disguise is well chosen. A crash-reporting prompt is something Mac users see often and rarely question, which makes it an easy costume for a program whose real job is to empty a keychain and drain a wallet. Familiarity is what lets it run without a second thought.

For defenders and users, the takeaways are practical. Notarization raises the bar but is not proof of safety, so it should not switch off suspicion. Install software only from sources you actually trust, be wary of unexpected system-looking prompts, and on Macs that hold crypto or sensitive credentials, assume that infostealers now treat macOS as a first-class target, because they do.

Sources: The Hacker News, BleepingComputer.

Liked this briefing? Share it:

More briefings

Related posts appear on the live page
Get the briefings first
Breaking security news, verified fast, with the one fact the headlines skip. No spam - unsubscribe anytime.