Cybersecurity researchers from Jamf Threat Labs have identified "CrashStealer," a sophisticated macOS information stealer written in native C++. Distributed through a signed and Apple-notarized dropper disguised as "Werkbit.app," the malware leverages social engineering to bypass Gatekeeper checks. It employs advanced evasion techniques, including control-flow flattening and AES-GCM encryption, to resist analysis while communicating with a GitHub repository to stage its final payload.
The malware harvests extensive sensitive data, targeting credentials from various browsers, over 80 cryptocurrency wallet extensions, and 14 major password managers. It also extracts files from the user's Documents and Downloads directories. After validating the victim's login password locally, the stolen data is exfiltrated to an external server. This campaign underscores the increasing complexity of macOS-targeted threats and the use of notarized binaries to gain initial access.
Top comments (0)