💻
macOS malware CrashStealer impersonates Apple crash tool to steal your data
💻 Technology

macOS malware CrashStealer impersonates Apple crash tool to steal your data

Cybersecurity firm Jamf has uncovered a new macOS infostealer called CrashStealer, written in C++ and disguised as Apple's CrashReporter tool. It is distributed via a fake software site called "Werkbit Setup," bypasses Apple's Gatekeeper, and installs a LaunchAgent. A fake password prompt then unlocks the Keychain, allowing the malware to exfiltrate credentials, cookies, browser data, and information from over 80 crypto wallets and 14 password managers.

Comments

No comments yet