New Malware Threat Targeting Apple Devices Exploits Apple Notarization

Mac users are being targeted by a new form of malware that impersonates Apple's built-in crash reporting feature.

This new malware, CrashStealer, is a macOS infostealer that harvests login details, cryptocurrency wallets, and any other account data stored on the system or in browsers.

CrashStealer is delivered through a disk image that imitates Apple's crash reporting component. Its aim is to trick users into installing the password stealing payload.

Its initial attack chain was unclear at first. However, some researchers traced one of the websites users visited, finding it posed as a legitimate platform to distribute the video conference tool Werkbit. Before downloading off the website, certain users are given a special meeting PIN. How victims are selected to get this PIN remains unknown.

The second stage of the attack involves the user being directed to a signed and Apple notarized dropper, distributed as a "Werkbit Setup" disk image. This disk image is signed with a valid Apple developer ID and a notarization ticket. This allows it to use the macOS security feature, Apple Gatekeeper, which is designed to prevent malware execution.

The user is then encouraged to run an application which is designed to look exactly like a legitimate software installer. Once installed, the application reaches out to a GitHub API which decodes a jumbled script, that decoded script becomes a downloader-installer that then gets the CrashStealer payload.

Once the infostealer is on the device, it displays a password prompt designed to resemble an actual macOS authorization request. Once the device's system login credentials are confirmed, the infostealer begins its objective: stealing usernames, passwords, password manager logins, cryptocurrency wallets, any credentials stored on the device, and any other keychain data that provides account access.

Source: https://www.infosecurity-magazine.com/news/macos-malware-apple-crash-reporter/; https://www.kaspersky.com/blog/crashstealer-werkbit-macos-infostealer/56217/

Commentary

The most important part of this infostealer is not exactly what it steals, but rather how it is built.

The presence of a developer ID shows that the application was signed by a developer who purchased a signing certificate, using that to cryptographically sign the malicious application. These steps make the application appear more legitimate.

Infostealers commonly skip this step. It requires purchasing a certificate and requires submitting the app to Apple's notarization servers. Many do not bother to do so.

The benefit of going through this process for cybercriminals is fewer security prompts when the victim attempts to open the application.

The infostealer further evades detection by impersonating Apple's built-in crash reporter.

Organizations utilizing Apple devices should ensure their staff is aware of this new malware threat and are prepared with strong cybersecurity training.

One of the most important things organizations can do to prevent against this threat is to carefully research and verify apps before installing them. This includes primarily using utilities/apps from official app stores whenever possible.

The final takeaway is that organizations using Apple devices should keep up to date regarding this new malware threat.

Finally, your opinion is important to us. Please complete the opinion survey:

What's New

New Malware Threat Targeting Apple Devices Exploits Apple Notarization

A new malware threat uses a developer ID and poses as a legitimate Apple crash reporter to trick users. We examine how the malware works and what organizations that use macOS should do.

Using AI To Code Generates Higher Malware Risk: How Should Organizations Respond?

A recent study reveals significant malware risk exists associated with AI in coding. We examine the statistics and discuss the loss prevention options.

AI Malware May Be The New Hot Scam, But Don't Forget The Classics

AI has been getting much media attention in the cybersecurity sphere; however, the cyber attack basics are still legitimate risks, and they are not going away. We discuss those risks and what organizations need to know.

Latest Numbers

  • Unemployment Rate
    4.3% in Jan 2026
  • Payroll Employment
    +130,000(p) in Jan 2026
  • Average Hourly Earnings
    +$0.15(p) in Jan 2026
  • Employment Cost Index (ECI)
    +0.7% in 4th Qtr of 2025
  • Productivity
    +4.9% in 3rd Qtr of 2025

Source: Department of Labor