CrashStealer poses as Apple crash reporting and empties the Keychain on Mac
Kaspersky described CrashStealer on 3 August 2026, an information stealing malware for macOS. It is distributed through Werkbit Setup, a fake videoconferencing installer that is signed and notarized so that it appears trustworthy. Once installed it impersonates Apple's CrashReporter and uses a convincing password prompt to reach the victim's Keychain. From there it takes browser credentials, password manager data, cookies and cryptocurrency wallets, while establishing persistence and concealing its activity.
What happens technically
macOS has two layers meant to prevent exactly this. Gatekeeper checks that the program is signed by an identified developer, and notarization means Apple has run an automated check of the contents without finding known malware. Kaspersky states that the installer behind CrashStealer is both signed and notarized. The visible warnings are then gone, and the user receives a program that looks as legitimate as any other.
The next step is the key to the attack. The macOS Keychain is encrypted, and no program reaches into it without the user approving. CrashStealer solves that by asking the user for the password in a dialog that looks like a system message from Apple crash reporting. This is social engineering turned into a system, because a Mac user is accustomed to typing that password into such boxes several times a week. Once the malware has the password the rest follows. Browser credentials, password manager contents, cookies that grant access to already authenticated services, and keys to cryptocurrency wallets then lie open. Kaspersky further states that the malware establishes persistence and conceals its activity, meaning it survives a restart and is built to stay.
What this means for you if you manage the Macs
If you still believe Macs are not targeted, this is the moment to set that belief aside. It has not held for some time. Berigo has previously covered PamStealer, which posed as an ordinary Mac utility, and Python based information stealers increasingly aimed at macOS. CrashStealer fits that pattern and adds something uncomfortable. The malware abuses Apple's own trust mechanisms rather than evading them, and the signature is then no longer an answer to whether the program is safe.
Our assessment is that your Macs have to enter the same management as the rest of your fleet. In practice that is three things. Central management of the machines, detection that actually runs on macOS, and a rule about where software may come from. The last one is often the weakest link, because Mac users in many organisations install software themselves. The second consequence is that a single password can cost you more than the machine. The Keychain is the door into everything the user has signed into, and stolen cookies grant access without a fresh login. If your organisation is covered by NIS2, this is endpoint security and access control under Article 21, whichever operating system the client runs.
Berigo recommends
- Bring Mac machines into central management, with an overview of which programs are actually installed.
- Introduce detection that works on macOS, and send the events to the same place as the events from Windows.
- Limit where software may be obtained from, and let videoconferencing clients come from a known source or an internal catalogue.
- Teach staff that a password prompt appearing without them starting anything is an alert, not a routine.
- Treat a Mac infected by an information stealer as an account compromise, with password changes and revocation of active sessions.
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch