CrashStealer Fakes macOS Crash Reporter to Steal Passwords

IT News Australia · High sophistication
Last updated July 30, 2026

Researchers found a macOS infostealer that disguises itself as a legitimate collaboration app and then impersonates Apple’s crash-reporting tools. After the user installs it, the malware shows a convincing macOS password prompt to trick the user into entering their password, then steals keychain and browser credentials.

How the attack worked

CrashStealer begins as a fake collaboration app called Werkbit, distributed through a PIN-gated disk image that adds a layer of false legitimacy to the installation process. Once installed, the malware does not immediately ask for anything unusual. Instead, it impersonates Apple's own crash-reporting component, copying its bundle identifier, icon, and even installing a LaunchAgent named to look like a genuine Apple system process.

With that disguise in place, CrashStealer displays a fake macOS password prompt. The prompt includes explanatory text written by the malware's developer specifically to make a request for broad system access sound like routine maintenance rather than a credential grab. Once a user enters their password, it is verified locally and then used to unlock Keychain data and credentials stored in user folders.

Why it succeeded

Several layers of manufactured trust make this attack effective:

  • The app was signed and notarised through an Apple developer account, which allowed it to bypass macOS Gatekeeper warnings until Apple revoked the credentials.
  • It impersonated a core Apple system component rather than a third-party tool, borrowing the credibility users associate with built-in macOS processes.
  • The PIN-gated installer created an impression of exclusivity or official process, discouraging suspicion.
  • The password prompt's wording was crafted to sound like ordinary system maintenance, not a security-sensitive action.

Because each of these elements reinforces the others, a user who might question one signal in isolation is less likely to question the combination.

What to watch for

Defenders and everyday macOS users should be alert to:

  • Any newly installed application asking for your macOS password shortly after installation, especially framed as maintenance or a system update.
  • Installers that require unusual steps, such as a PIN, to proceed, which can be used to simulate an official or vetted process.
  • Apps claiming to be collaboration or productivity tools that do not actually provide meaningful collaboration features.
  • Reliance on notarisation as a sole indicator of trust. Notarisation confirms code signing, not that the software itself is legitimate.

Building resistance

Organisations with macOS endpoints should reinforce that password prompts appearing after installing a new app are not routine and should be verified with IT before any credentials are entered. Security awareness efforts should also cover how attackers can fake legitimacy through corporate-looking websites, claimed customer logos, or valid-seeming signing credentials, since none of these alone confirm that software is safe. Encouraging users to pause and verify the source of an installer, particularly one that adds artificial friction like a PIN gate, can reduce the chance that a convincing disguise leads to a real credential compromise.

Key findings

  • The malware masquerades as a collaboration app called “Werkbit” and uses a “PIN-gated” installer to appear legitimate.
  • It is signed and notarised via an Apple developer account to bypass macOS Gatekeeper warnings (until Apple revoked the credentials).
  • The payload impersonates Apple’s crash-reporting component (bundle identifier, icon, and a LaunchAgent) to appear trusted.
  • It shows a fake macOS password prompt and verifies passwords locally, then steals Keychain data and credentials from user folders.
  • Jamf observed infrastructure suggesting continued campaigns, including lookalike domains and possible Windows variants.

Who’s being targeted

  • Commonly targeted roles: All employees using macOS, Executive leadership, IT / Helpdesk, Security awareness.
  • Affected industries: Any organisation with macOS endpoints.
  • Attack channels: website.
  • Impersonated: Apple macOS Crash Reporter / trusted Apple system component.

Red flags to watch for

  • A newly installed app requesting your macOS password for “routine maintenance”
  • A “PIN-gated” installer used to create false legitimacy
  • An app claiming to be a collaboration tool but providing no real collaboration features
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is CrashStealer?

CrashStealer is a macOS infostealer that disguises itself as a collaboration app called Werkbit and then impersonates Apple's crash-reporting component to steal Keychain and browser credentials.

How does CrashStealer trick users into giving up their password?

After installation, it displays a fake macOS password prompt with explanatory text designed to make the request for broad system access sound like routine maintenance.

Does Apple notarisation mean an app is safe?

No. CrashStealer was signed and notarised via an Apple developer account, which helped it bypass Gatekeeper warnings until Apple revoked the credentials, showing notarisation alone does not vet the software.

What are the warning signs of this attack?

Red flags include a newly installed app requesting your macOS password for routine maintenance, a PIN-gated installer used to add false legitimacy, and a collaboration tool that provides no real collaboration features.

Read the video transcript

On a Mac, would you trust a crash popup that looks exactly like Apple’s own Crash Reporter? CrashStealer hides inside a fake collaboration app called Werkbit. You download a PIN-gated Werkbit.dmg, it’s signed and notarised, looks corporate, then suddenly a “com.apple.crashreporter.helper” popup asks for your Mac password. Here’s the trick: that fake crash prompt isn’t fixing anything. CrashStealer verifies your password locally, then quietly raids your Keychain and browser folders for saved logins and sends them off. If any new app like Werkbit suddenly pops a crash or maintenance prompt asking for your Mac password, stop. Don’t type it, screenshot it and send it to IT to verify first.

Similar attacks

CrashStealer Hides as Apple Crash Reporter

CrashStealer Hides as Apple Crash Reporter

Researchers found a real macOS infostealer campaign that tricks users into running a signed, Apple-notarized app (“Werkbit Setup”) that passes Gatekeeper and…

July 14, 2026
Fake Mac Crash Reporter Steals Passwords

Fake Mac Crash Reporter Steals Passwords

Researchers warn about a new macOS infostealer called “CrashStealer” that pretends to be Apple’s Crash Reporter. It uses a legitimate-looking installer and a…

July 15, 2026
Fake Teams Update Drops Remote-Access Tools

Fake Teams Update Drops Remote-Access Tools

Researchers reported a real phishing campaign (“Operation BlueDash”) that tricks users with a “secure document” lure and routes them to a fake Microsoft Store…

July 27, 2026