Close Menu
  • Breaking News
  • Business
  • Personal Finance
  • 2nd Amendment
  • Videos
  • Forum
  • More
    • Prepping & Survival
    • Health
    • Top Stocks
    • Stocks Portfolio

Subscribe to Updates

Get the latest news and updates directly to your inbox.

Popular Now
JJ McCarthy considered ‘unpredictable’ as Vikings hand starting QB role to Kyler Murray: report Breaking News

JJ McCarthy considered ‘unpredictable’ as Vikings hand starting QB role to Kyler Murray: report

By Dewey LewisAugust 15, 20260

NEWYou can now listen to Fox News articles! It may not have come as a…

Cardinals rookie makes MLB history by hitting a home run in each of his first three career plate appearances

Cardinals rookie makes MLB history by hitting a home run in each of his first three career plate appearances

August 15, 2026
Cardinals top pick Jeremiyah Love out for a least a week after suffering preseason injury, coach says

Cardinals top pick Jeremiyah Love out for a least a week after suffering preseason injury, coach says

August 15, 2026
Dolly Parton’s ongoing health battle forces country legend to miss major Dollywood event

Dolly Parton’s ongoing health battle forces country legend to miss major Dollywood event

August 15, 2026
Facebook X (Twitter) Instagram
Trending
  • JJ McCarthy considered ‘unpredictable’ as Vikings hand starting QB role to Kyler Murray: report
  • Cardinals rookie makes MLB history by hitting a home run in each of his first three career plate appearances
  • Cardinals top pick Jeremiyah Love out for a least a week after suffering preseason injury, coach says
  • Dolly Parton’s ongoing health battle forces country legend to miss major Dollywood event
  • Retired Navy SEALS plunge into New York Harbor for patriotic swim honoring service and sacrifice
  • Pro wrestler LaBron Kozone talks decision to sign with MLW, getting called ‘generational’ prospect
  • Prepare for the Economic Squeeze Before It Gets Worse
  • Exclusive: Israel seizes vast Iran terror axis arsenal with surprising foreign origins
Facebook X (Twitter) Instagram LinkedIn VKontakte
Saturday, August 15
Republican Investor
Banner
  • Breaking News
  • Business
  • Personal Finance
  • 2nd Amendment
  • Videos
  • Forum
  • More
    • Prepping & Survival
    • Health
    • Top Stocks
    • Stocks Portfolio
Subscribe
Republican Investor
You are at:Home » CrashStealer Mac malware steals passwords and wallets
Breaking News

CrashStealer Mac malware steals passwords and wallets

Dewey LewisBy Dewey LewisJuly 21, 2026No Comments9 Mins Read
Facebook Twitter LinkedIn Tumblr Reddit WhatsApp
CrashStealer Mac malware steals passwords and wallets
Share
Facebook Twitter LinkedIn Pinterest Email

NEWYou can now listen to Fox News articles!

A polished installer can make risky software feel routine. You see a familiar Mac window, follow the directions and enter your password when asked. By then, the app may already be working against you.

Security researchers at Jamf Threat Labs have uncovered CrashStealer, a new Mac information stealer that impersonates Apple’s crash-reporting software. Jamf first tracked the malware in May 2026 while it appeared to be under development. By early July, researchers detected it in active attacks.

Free live CyberGuy class: Sick of Spam? Join us July 22

Join us this Wednesday, July 22, at 1 PM ET for a free CyberGuy Live class that will help you cut down on robocalls, spam texts, junk email and other unwanted messages. Kurt “CyberGuy” Knutsson will walk you step by step through simple ways to filter spam, clean up your inbox and recognize the messages that could put your personal information at risk. No technical experience is needed. You’ll also receive our spam-stopping checklist, and every registrant will get a link to the class recording afterward.

Reserve your free spot today at CyberGuyLive.com .

REDHOOK ANDROID MALWARE CAN QUIETLY HIJACK YOUR PHONE

What is CrashStealer Mac malware?

CrashStealer targets information many people rely on every day. It searches for browser credentials, password-manager data and cryptocurrency wallet information. The malware can copy the Mac login Keychain as well. The malware stands out because its developers wrote it in native C++. Many common Mac stealers rely on AppleScript or simpler software wrappers.

CrashStealer also encrypts the files it collects before sending them to an attacker-controlled server. Meanwhile, anti-debugging features make the malware harder for researchers to examine. However, the first app a victim sees isn’t called CrashStealer. The attack begins with a disk image branded as “Werkbit Setup.”

How CrashStealer Mac malware infects computers

The Werkbit Setup disk image contains a polished installer. Its directions tell the user to right-click the app and choose Open. That action often appears in instructions for software that needs to get around a Mac security warning. In this case, the installer already carried a valid Apple Developer ID and a notarization ticket. Therefore, it could clear Gatekeeper on its first launch. Jamf also found that the disk image itself had been signed, which researchers called unusual for malicious Mac delivery.

The website that distributed Werkbit Setup required a meeting PIN. That setup may have helped the attackers limit access to people who received the correct code. It also made the download feel more exclusive and potentially more believable.

Once opened, Werkbit Setup contacted GitHub for an initial command. It then downloaded a script from the attackers’ infrastructure. Next, the script installed a second disk image named CrashReporter.dmg in a hidden temporary folder. The payload used the name CrashReporter and the bundle identifier com.apple.crashreporter. Those details were chosen to resemble an Apple system component. The malware then launched quietly in the background.

How the malicious Mac installer cleared Gatekeeper

Apple uses Gatekeeper alongside Developer ID signing to reduce the risk from downloaded software. Its notarization process checks an app for known malicious content when developers submit it. Gatekeeper can also check whether Apple has revoked the signing certificate. Still, a notarized label should never replace your judgment about where an app came from.

A harmful app can slip through before researchers or Apple identify its behavior. Attackers can also use a trusted first-stage installer to retrieve a different payload after launch. Jamf reported the Developer Team ID connected to Werkbit Setup to Apple after confirming that it had distributed malicious software. The report did not say how many people had been infected.

CrashStealer uses a fake Mac password prompt

After CrashStealer launches, it displays a password prompt designed to resemble a legitimate macOS authorization request. The malware checks the password locally with a built-in Mac directory service command.

If the password is wrong, the prompt returns. If it is correct, CrashStealer stores an obfuscated copy and uses the credential to unlock the login Keychain.

The malware can then copy the Keychain database into its collection folder. That makes the prompt one of the most important warning signs. A password request can look convincing, yet the timing may feel wrong. An online meeting installer should not need your Mac password to display a call or download ordinary content.

What data CrashStealer steals from a Mac

CrashStealer searches broadly across the Mac. Jamf found code and activity tied to Chromium-based browsers, Safari data and Firefox credential files. The malware also checked wallet extensions such as MetaMask and Phantom. In addition, it targeted password managers that included 1Password, Bitwarden, LastPass and Dashlane. Jamf observed roughly 80 cryptocurrency wallet extensions and 14 password managers in the target list.

A separate file-search tool scans locations such as Documents and Downloads. However, it skips many large installers, apps and media files. That filtering suggests the thieves want compact files that may contain credentials or financial records. Other personal documents may also appeal to the attackers.

How CrashStealer hides stolen data

CrashStealer stores stolen material inside hidden folders under the user’s home directory. It encrypts each collected item with AES-256-GCM. Then it packages groups of encrypted files into hidden ZIP archives before uploading them. Encryption helps the attackers conceal the contents of the stolen files while they sit on the Mac. It also means a leftover archive can confirm that collection occurred even when an investigator cannot read the data inside it.

The malware then copies itself into the Mac’s Library cache folder. It creates a LaunchAgent that starts the copied app when the user logs in. The LaunchAgent uses an Apple-like name, which can make the entry blend in during a quick inspection.

HALLUSQUATTING AI ATTACK COULD HIJACK YOUR COMPUTER

Person finding malware on their computer.

Warning signs of CrashStealer Mac malware

You may have encountered this campaign after downloading Werkbit Setup. The risk rises if the website required a meeting PIN. An unexpected CrashReporter password prompt is another red flag. Be more suspicious when the prompt appears right after installing unrelated software or joining an online meeting.

Also, watch for an unfamiliar app asking for Full Disk Access or permission to reach Documents and Downloads. CrashStealer’s configuration included permission messages designed to make broad file access sound necessary for “system administration.” Security teams can also look for the hidden CrashReporter locations and LaunchAgent described in Jamf’s technical report. However, most home users should avoid digging through system folders unless they know exactly what they are changing.

Ways to stay safe from CrashStealer Mac malware

A few careful habits can help you spot a suspicious Mac installer before it gets access to your passwords and personal files.

1) Download Mac apps from verified sources

Use the Mac App Store when possible. Otherwise, type the developer’s official website address yourself. Avoid downloading software from a meeting link, private message or unexpected pop-up unless you can independently confirm the source.

2) Do not override Mac security warnings automatically

Be wary when an installer tells you to right-click and choose Open or use the Open Anyway button. Apple recommends overriding a security warning only when you trust the app’s source. You should also confirm that nobody altered the download.

3) Pause before entering your Mac password

Look at which app triggered the prompt and why it needs authorization. Cancel the request when the reason does not match what you are doing. Then close the app and verify the download with the company through a separate channel.

4) Review powerful Mac app permissions and login settings

Open the Apple menu > System Settings > Privacy & Security . Review Full Disk Access , Files & Folders and Accessibility for apps you do not recognize. Turn off access for anything suspicious.

Next, open System Settings > General > Login Items & Extensions . Review the apps listed under Open at Login and Allow in the Background . Remove or disable unfamiliar entries.

You can also check System Settings > General > Device Management for profiles you do not recognize. This option may appear only when a profile is installed. Do not remove a work or school profile without contacting the administrator first.

5) Install the latest macOS security updates

Open the Apple menu > System Settings > General > Software Update . Install available updates promptly because they include current security protections.

6) Use strong antivirus software on your Mac

A trusted antivirus program can help detect known malicious files, suspicious persistence and harmful network behavior. Keep real-time protection enabled and allow the software to update automatically. Jamf says threat-prevention tools can help block and report similar Mac threats. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com

7) Act quickly if you installed Werkbit Setup

Disconnect the Mac from the internet. Do not enter another password on that computer. Run a full scan with trusted security software. You should also contact Apple Support or your workplace IT team.

Next, use a clean device to change the password for your Apple Account, primary email account and password manager. Change passwords for banking, shopping and other sensitive accounts that were saved on the affected Mac. Enable two-factor authentication (2FA) where available and sign out of devices or active sessions you do not recognize.

After the Mac has been cleaned, change its login password because CrashStealer may have captured and validated that credential.

If you use cryptocurrency wallets on the affected Mac, treat their private keys and recovery phrases as exposed. Move remaining funds to newly created wallets from a clean device. Never reuse the old recovery phrase.

If security software cannot confirm that CrashStealer has been fully removed, contact Apple Support or a qualified technician about erasing the Mac and reinstalling macOS. Restore personal files carefully from a backup created before the infection, when possible.

FBI HELPS TAKE DOWN AI PHISHING RING

Person typing on their laptop.

Kurt’s key takeaways

CrashStealer shows how attackers can wrap harmful software in a convincing Mac experience. The signed Werkbit installer gave the campaign a layer of credibility. Then the fake crash reporter used a familiar password prompt to reach valuable data on the computer. Your best defense begins before the password prompt appears. Verify the source of every installer and stop when the instructions ask you to bypass a warning. Strong antivirus protection and current macOS updates add another barrier.

Would Apple notarization earn your trust, or would you still question a polished Mac installer? Let us know by writing to us at Cyberguy.com

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Sign up for my FREE CyberGuy Report

Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.

For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.

Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.

Copyright 2026 CyberGuy.com. All rights reserved.

Read the full article here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleMiami’s cost of living now tops New York City’s despite Florida’s tax advantages
Next Article Kai Trump reveals diet and nutrition secrets that created six-pack abs post-surgery

Related Posts

JJ McCarthy considered ‘unpredictable’ as Vikings hand starting QB role to Kyler Murray: report

JJ McCarthy considered ‘unpredictable’ as Vikings hand starting QB role to Kyler Murray: report

August 15, 2026
Cardinals rookie makes MLB history by hitting a home run in each of his first three career plate appearances

Cardinals rookie makes MLB history by hitting a home run in each of his first three career plate appearances

August 15, 2026
Cardinals top pick Jeremiyah Love out for a least a week after suffering preseason injury, coach says

Cardinals top pick Jeremiyah Love out for a least a week after suffering preseason injury, coach says

August 15, 2026
Dolly Parton’s ongoing health battle forces country legend to miss major Dollywood event

Dolly Parton’s ongoing health battle forces country legend to miss major Dollywood event

August 15, 2026
Retired Navy SEALS plunge into New York Harbor for patriotic swim honoring service and sacrifice

Retired Navy SEALS plunge into New York Harbor for patriotic swim honoring service and sacrifice

August 15, 2026
Pro wrestler LaBron Kozone talks decision to sign with MLW, getting called ‘generational’ prospect

Pro wrestler LaBron Kozone talks decision to sign with MLW, getting called ‘generational’ prospect

August 15, 2026
Add A Comment

Comments are closed.

Follow us
  • Facebook
  • Twitter
  • Instagram
  • Pinterest
Highlights
Cardinals rookie makes MLB history by hitting a home run in each of his first three career plate appearances Breaking News

Cardinals rookie makes MLB history by hitting a home run in each of his first three career plate appearances

By Dewey LewisAugust 15, 20260

NEWYou can now listen to Fox News articles! St. Louis Cardinals rookie Joshua Báez’s first…

Cardinals top pick Jeremiyah Love out for a least a week after suffering preseason injury, coach says

Cardinals top pick Jeremiyah Love out for a least a week after suffering preseason injury, coach says

August 15, 2026
Dolly Parton’s ongoing health battle forces country legend to miss major Dollywood event

Dolly Parton’s ongoing health battle forces country legend to miss major Dollywood event

August 15, 2026
Retired Navy SEALS plunge into New York Harbor for patriotic swim honoring service and sacrifice

Retired Navy SEALS plunge into New York Harbor for patriotic swim honoring service and sacrifice

August 15, 2026

Subscribe to Updates

Get the latest news and updates directly to your inbox.

About
About

Republican Investor is one of the top news portals to cover business, personal finance and second amendment news, follow us to get the latest news.

We're social, connect with us:

Facebook X (Twitter) Instagram LinkedIn VKontakte
Popular Posts
JJ McCarthy considered ‘unpredictable’ as Vikings hand starting QB role to Kyler Murray: report

JJ McCarthy considered ‘unpredictable’ as Vikings hand starting QB role to Kyler Murray: report

August 15, 2026
Cardinals rookie makes MLB history by hitting a home run in each of his first three career plate appearances

Cardinals rookie makes MLB history by hitting a home run in each of his first three career plate appearances

August 15, 2026
Cardinals top pick Jeremiyah Love out for a least a week after suffering preseason injury, coach says

Cardinals top pick Jeremiyah Love out for a least a week after suffering preseason injury, coach says

August 15, 2026
Latest News
Dolly Parton’s ongoing health battle forces country legend to miss major Dollywood event

Dolly Parton’s ongoing health battle forces country legend to miss major Dollywood event

August 15, 2026
Retired Navy SEALS plunge into New York Harbor for patriotic swim honoring service and sacrifice

Retired Navy SEALS plunge into New York Harbor for patriotic swim honoring service and sacrifice

August 15, 2026
Pro wrestler LaBron Kozone talks decision to sign with MLW, getting called ‘generational’ prospect

Pro wrestler LaBron Kozone talks decision to sign with MLW, getting called ‘generational’ prospect

August 15, 2026
Copyright © 2026. Republican Investor. All rights reserved.
  • Privacy
  • Terms of use
  • Press Release
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.