Last updated: August 19, 2026 at 1:47 AM UTC
All 741 Vulnerability 286 Breach 129 Threat 319 Defense 7
Tag: crashstealer (1 article)Clear

CrashStealer Mac malware uses an Apple-notarized app to slip past Gatekeeper

Jamf detailed CrashStealer, a macOS infostealer delivered through a signed, Apple-notarized app called Werkbit that passes Gatekeeper, since it carried a valid developer ID before Apple revoked it. Distributed as a disk image and gated behind a meeting PIN so it is served only to targeted visitors, the malware validates the victim's login password locally, then harvests broadly from browsers, cryptocurrency wallets, password managers, and the keychain, encrypting the loot before sending it out. It persists by copying and re-signing itself. There is no zero-click stage: a victim still runs the app and enters their password, but the notarized delivery and careful targeting make it more convincing than typical Mac stealers.

Check
Remind Mac users that notarization does not guarantee an app is safe, to be cautious of apps delivered by disk image behind meeting codes, and to refuse password prompts from unexpected installers.
Affected
Mac users who download and run the notarized Werkbit app and enter their password; CrashStealer then steals browser data, crypto wallets, password-manager contents, and keychain secrets, and reinstalls itself to persist.
Fix
Install apps only from trusted sources, treat unexpected password and disk-image prompts with suspicion, keep macOS and endpoint tools updated to catch known indicators, and monitor for apps copying and re-signing themselves.