T

Threats

macOS CrashStealer Infostealer Identified in Active Use

Secure ISS is proactively sharing Jamf Threat Labs' latest research into a new macOS infostealer, in the interest of awareness and good security hygiene. For awareness only, no immediate action required.


Overview

Advisory Type: Threat Research Awareness

Date: 20 July 2026

Researcher: Jamf Threat Labs

Jamf Threat Labs has identified a new macOS infostealer, tracked as CrashStealer,that has progressed from development into active use.

The malware is designed to steal browser credentials, cryptocurrency wallet information, password-manager data, files and macOS Keychain material.

Initial access occurs through a disk image presented as "Werkbit Setup". The installer uses a valid Apple Developer ID and was notarised by Apple, allowing it to clear Gatekeeper when first launched. It then downloads and installs CrashStealer, which impersonates Apple's legitimate Crash Reporter component and runs from a hidden directory.

Once running, CrashStealer presents a password prompt designed to resemble a genuine macOS authorisation request. It validates the password locally, uses it to unlock the user's login Keychain and collects information from browsers, cryptocurrency wallets, password managers, and selected user directories. The stolen data is encrypted before being sent to attacker-controlled infrastructure.


What Jamf Has Identified

  • CrashStealer is a native C++ macOS infostealer observed in active use.

  • The malware is distributed through a signed and Apple-notarised installer presented as “Werkbit Setup”.

  • The installer downloads a payload that impersonates Apple’s Crash Reporter component.

  • CrashStealer uses a fraudulent password prompt to capture and validate the user’s macOS login password.

  • It targets browser credentials, cryptocurrency wallets, password managers, Keychain data and selected files.

  • Collected information is encrypted using AES-256-GCM before exfiltration.

  • The malware can establish persistence through a LaunchAgent and a copy stored under the user’s Library directory.

  • Jamf reported the Developer Team ID used to distribute the malicious installer to Apple.


Recommended Actions

  • No immediate technical action is required unless the identified software or indicators are present in your environment.

  • Confirm that macOS devices are covered by endpoint protection and appropriate monitoring.

  • Remind users to install software only from known and trusted sources. A valid developer signature or Apple notarisation should not be treated as proof that an application is safe.

  • Investigate any installation or execution of software presented as “Werkbit Setup”, particularly downloads associated with werkbit[.]io.

  • Monitor for applications launching from hidden paths such as /private/tmp/.CrashReporter/.

  • Review Jamf’s published technical indicators and detection guidance for use in endpoint monitoring and threat-hunting activities.

  • If CrashStealer is suspected on a device, isolate the affected endpoint and treat the user’s macOS password, browser credentials, stored Keychain secrets, password-manager data and cryptocurrency wallets as potentially compromised.


Reference

Need help?

Please get in touch on 1300 769 460 or email us. We are here to help you strengthen your cybersecurity posture.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.