CRASHSTEALER is a newly identified macOS infostealer developed in C++ that disguises itself as an Apple crash reporter, targeting macOS users, especially those involved in cryptocurrency. It utilizes a notarized dropper to bypass security measures, allowing it to steal browser data, crypto wallets, and passwords. Initial access is gained through a legitimate-looking disk image, which once opened, fetches additional payloads and stages itself on the system.
The malware has various data theft capabilities including targeting popular browser extensions and password managers. Stolen data is encrypted and sent to a hardcoded command-and-control server. There is currently no attribution to a specific threat actor, though it is considered part of a broader, organized operation.