Mac owners should be on the lookout, as security experts have warned of a new malware called CrashStealer that masquerades as a legitimate tool from Applu and tries to extract login credentials from users. Once it has obtained them, it can access passwords, web browser data, cryptocurrency wallets, and other sensitive information.
You might be interested in
According to researchers at Jamf Threat Labs, the attack was spread through the Werkbit application, which was digitally signed and even went through a process Apple Notarization. This means that macOS considered it trustworthy and did not display the standard security warning when it was launched. Only after the application was launched did the actual malicious code download to the computer, which then pretended to be the system tool CrashReporter.
The most dangerous part of the attack comes when the malware displays a fake system window asking for your Mac password. The dialog looks virtually identical to the official macOS prompts, so many users may not even realize it’s a scam. If they enter their password, the malware verifies it and then gains access to Keychain, saved passwords, browser data, and files in the Documents and Downloads folders. It also targets data from popular password managers and cryptocurrency wallets.
You might be interested in
The good news is that Apple after reporting the case, it revoked the relevant certificates, so that the malware can no longer spread in the same way. Nevertheless, experts recommend downloading applications only from trusted sources and being cautious every time a newly installed application unexpectedly asks for a system password. CrashStealer primarily relies on user trust and, according to available information, does not exploit any security flaws in macOS itself.