CrashStealer Mac malware uses an Apple-notarized app to slip past Gatekeeper
Jamf detailed CrashStealer, a macOS infostealer delivered through a signed, Apple-notarized app called Werkbit that passes Gatekeeper, since it carried a valid developer ID before Apple revoked it. Distributed as a disk image and gated behind a meeting PIN so it is served only to targeted visitors, the malware validates the victim's login password locally, then harvests broadly from browsers, cryptocurrency wallets, password managers, and the keychain, encrypting the loot before sending it out. It persists by copying and re-signing itself. There is no zero-click stage: a victim still runs the app and enters their password, but the notarized delivery and careful targeting make it more convincing than typical Mac stealers.
- Check
- Remind Mac users that notarization does not guarantee an app is safe, to be cautious of apps delivered by disk image behind meeting codes, and to refuse password prompts from unexpected installers.
- Affected
- Mac users who download and run the notarized Werkbit app and enter their password; CrashStealer then steals browser data, crypto wallets, password-manager contents, and keychain secrets, and reinstalls itself to persist.
- Fix
- Install apps only from trusted sources, treat unexpected password and disk-image prompts with suspicion, keep macOS and endpoint tools updated to catch known indicators, and monitor for apps copying and re-signing themselves.