New CrashStealer malware pretends to be Apple's Crash Reporter: Header image
Emerging Threats 8 min read

New CrashStealer malware pretends to be Apple’s Crash Reporter

Published:Jul 24, 2026

A new active stealer campaign is targeting Mac users, tricking them into installing new stealer malware that targets your crypto and data. The bad actors behind this threat are luring users with fake interviews and could be using other methods.

The new malware spoofs Apple’s built-in crash reports framework to access your files and data and decrypt the passwords it steals. Here’s what you need to know to stay safe. 

article snippet with Moonlock logo

Keep your Mac safe in the age of stealers

New stealer malware is targeting Macs every week. Protect yourself from data and identity theft with Moonlock. It keeps an eye on your Mac 24/7, blocking any malware that’s trying to get in.
try 7 days free

CrashStealer lures users via fake interviews on LinkedIn

Recently, Jamf Threat Labs reported that a new stealer, tracked as CrashStealer, was impersonating the macOS built-in crash report feature and targeting crypto, files, keychain data, and browser data. 

Following up on Jamf’s report, we found that the bad actors in this campaign were using fake interviews for fake jobs posted on LinkedIn by fake companies. The fake recruiters tell those interested in the job to download a video meeting app called Werkbit. Downloading this app triggers a series of cascading events, allowing CrashStealer to breach your Mac. 

A screenshot of the CrashStealer site https://werkbit[.]org, live when this report was written.
A screenshot of the CrashStealer site https://werkbit[.]org, live when this report was written but down when submitted to editorial. Image: Screenshot, Moonlock.

CrashStealer Timeline: From first scan to active cybercriminal infrastructure operation

Jamf said they first came across a CrashStealer sample in May. Back then, it was still under development. By June, a user on Reddit reported that he was targeted by CrashStealer in a rather complex cybercriminal fake interview operation that included fake phone calls.  

How CrashStealer operators trick you into installing the malware 

Unlike other stealers, this CrashStealer campaign does not seem to be using SEO poisoning or sponsored ads to lure users. Instead, based on Jamf’s article and users’ reports, threat actors are creating fake companies and fake jobs on LinkedIn.

A screenshot of a Reddit post about a user targeted by CrashStealer operators.
In June, a user reported on Reddit that he was targeted by CrashStealer operators. The user said the operators had a LinkedIn page and LinkedIn job posts. Image: Screenshot, Moonlock.

Users who were targeted in this campaign say the threat actors have even set up automated phone calls to try to trick you into installing the malware. The promise of a new job leads to a scam and a cyberattack.

Screenshot of the TradeUpToWallStreet LinkedIn account page.
The LinkedIn account of TradeUpToWallStreet was reported by a user as being used as a fake interview lure in a CrashStealer campaign in June. Image: Screenshot, Moonlock.

Also, unlike other stealer campaigns, CrashStealer does not use ClickFix techniques to breach your computer. Instead, scammers ask users to download the fake software or meeting app called Werkbit from a website, giving them a code.

A fake meeting app used as bait

When users click on the download button on the Werkbit site and enter the code, their browser downloads a lightweight disk image Mac file. The file manages to bypass built-in Mac security tools, including Gatekeeper, because the file and app are signed and notarized with a valid Apple developer ID, specifically that of Emil Grigorov (WWB7JA7AQV).

The malicious CrashStealer file does not contain the core engine of the malware. Instead, it acts as a payload fetcher connecting your Mac with online attacker-controlled infrastructure where the real malware components are hosted, automatically downloaded, and staged (installed) on your Mac. 

Threat actors created a fake site that attempts to pass as a meeting app solely to distribute CrashStealer. Jamf identified this site as: werkbit[.]io. The site was gone when we checked it. However, Jamf noted that several other sites existed in this campaign. 

Digging a little deeper, we did a simple online search for Werkbit and came up with top-of-page results for https://werkbit[.]org, a site that has exactly the same design and attack chain.

A screenshot of CrashStealer sites listed in search results.
There were active CrashStealer sites listed on DuckDuckGo and Google when this report was being written. Image: Screenshot, Moonlock.

The fake site not only offers downloads for Mac but for Windows as well.

A screenshot of the CrashStealer download page on https://werkbit[.]org, offered downloads for Mac and Windows.
The CrashStealer site https://werkbit[.]org offered Mac and Windows downloads, implying a cross-platform threat campaign. Image: Screenshot, Moonlock.

Jamf said that there are several domains out there distributing CrashStealer as part of a broader multi-platform campaign.

Fake interviews and stealers: Why Mac users should care

The fake job interview technique we see here is nothing new. Threat actors from North Korea have used the Contagious Interview and fake Zoom apps for years to launch similar attacks that target Mac users. This does not, however, mean that North Korean hackers are behind this campaign.

As Moonlock’s mid-2026 macOS threat report found, cybercriminals actively learn from state-sponsored threat groups. 

“LinkedIn recruitment lures, fake in-call fixes, fileless execution built to dodge detection—all of it originated in North Korean operations, and now, it’s widely used in criminal kits, often improved beyond the original versions,” the Moonlock mid-year threat report reads. 

What is Apple Crash Reporter on my Mac? CrashStealer’s main “thing” 

Media reports indicate that CrashStealer’s main “thing” is that it impersonates Apple Crash Reporter. This brings up some interesting points that, fortunately, can help you recognize a CrashStealer attack. Let’s break it down.  

The Jamf technical report explains that once CrashStealer is running on your Mac, it will create a fake Apple Crash Reporter icon. However, your Mac’s Crash Reporter is not an app. So this should be an immediate red flag.

So, what is Apple’s Crash Reporter? It’s a framework (code) built into your macOS that allows Apple to manage crash reports, collect crash information, run diagnostic reports, and collect and send feedback to Apple on bug reports that happen on your computer.

CrashStealer does not “hack” your Mac’s Crash Reporter framework at all. What it does is present itself as if it were part of those processes to trick you into typing your password. Here’s how it pulls that off.

How CrashStealer tricks its victims

Once CrashStealer installs a series of components and processes on breached devices, dressing them up as if they were part of the crash reporting framework, it generates fake macOS system notification popups that look just like the real thing. Under the excuse that “access is required,” the fake system notifications pressure you into typing in your passwords. This is not how normal software installations behave whatsoever.  

Pretending to be Crash Reporter, CrashStealer will ask you for the passwords for access to your Desktop, Documents, Downloads, and removable-volume access, as well as full disk access. CrashStealer needs these passwords to access your data and decrypt your credentials, which are otherwise password-encrypted.

Bottom line: If you install software on your Mac, and you get what appear to be system notifications asking you for passwords, do not type those in.

This hard-coded technique is how CrashStealer earned its name. 

A screenshot of CrashStealer posing as Mac Crash Reporter.
A Jamf screenshot shows how CrashStealer poses as your Mac’s Crash Reporter to attempt to steal your password. Image: Screenshot, Moonlock.

Jamf added that CrashStealer will check to see (validate) if the password you typed is correct, entering it locally on your Mac. If it is correct, the malware will use the password to unlock your login keychain.

As a reminder, your Mac login keychain, developed by Apple for macOS, allows you to store and manage passwords, certificates, and secure notes.  

CrashStealer can also scan for security tools, write a second copy of itself on your Mac, and re-sign that copy to avoid security detection, establishing persistence as a LaunchAgent and, therefore, surviving reboots. 

While most of the domains used in this fake interview multi-platform campaign are gone, the Command Panel of CrashStealer, used by those who operate this malware, is active.

A screenshot of the CrashStealer Command Panel.
The Command Panel of CrashStealer, which those who operate this malware use, is active. Screenshot, Moonlock.

How to keep safe from CrashStealer and other macOS stealers

Your first line of defense is to enable multi-factor authentication (MFA) on your accounts and keep your main crypto wallet off your Mac and on a separate device protected with biometrics or on a cold wallet. Other than that, there are several things you can do to stay safe from Mac stealers. 

Get Moonlock. It is updated to deal with emerging threats, new stealers, and variants. 

The Moonlock security app is constantly updated to keep up with new stealers, new malware variants, and emerging threats.

Screenshot of the the Moonlock app user interface.
The Moonlock app. Image: Screenshot, Moonlock.

Once installed, Moonlock’s Real-Time Protection will run in the background, silently cross-checking everything you interact with for suspicious activity. If it finds anything, the Moonlock app will let you know what it is and why it’s dangerous. You can also run configurable scans using the Malware Scanner and optimize for depth or speed. 

The Moonlock app also comes with a built-in VPN for safe browsing and a Scam Detector that can flag phishing in emails or text messages, helpful for detecting fake interview scams.

You can check out and test-drive Moonlock for free for 7 days.

Other tips and suggestions to stay safe from Mac stealers include password manager awareness, securing your crypto, and knowing when not to give your password away. Let’s look into these.

Password managers and crypto wallets can be breached 

CrashStealer is coded to go after around 80 crypto wallet extensions, including the top ones, such as MetaMask, Phantom, Coinbase, Trust Wallet, Rabby, OKX Wallet, Exodus, Keplr, Solflare, and Backpack, as well as 14 password managers including 1Password, Bitwarden, LastPass, Dashlane, Keeper, KeePassXC, NordPass, Enpass, and RoboForm. 

Other stealers can do the same. Do not consider crypto wallet extensions or crypto desktop applications unbreachable. The same goes for password managers. Instead, use MFA, biometrics, and keep your main crypto holdings off your Mac. 

Watch out for password requests 

As mentioned, CrashStealer will impersonate Apple’s Crash Reporter framework to trick you into giving away your passwords. This is not something done by CrashStealer alone; other stealers do the exact same thing using other techniques.

Your Mac passwords encrypt the data on your computer. Do not give away your passwords when installing new software.

Lures, lures, and more lures

Today, CrashStealer operators are using the fake interview technique to distribute the malware. Tomorrow, they might pivot, impersonate another brand, or use a different attack chain. So, how can you keep up?

Lures are where most cyberattacks begin. Whether via an email, an SMS, an ad online, or something else, be mindful of where a digital funnel begins to make sure it doesn’t end in the wrong place.

Final thoughts

CrashStealer is proof that the Mac threat landscape continues to be busy. Developing a new stealer, when there are plenty of those already on the dark web market, means there is demand for malware-as-a-service. This is not good news for the average Mac user.

Fortunately, the same principles that keep you safe from other stealers will hold their ground against this one. Always learn more about emerging threats and how your tech works to lead a calmer, safer, more productive digital life.

This is an independent publication, and it has not been authorized, sponsored, or otherwise approved by Apple Inc. Mac and macOS are trademarks of Apple Inc.

MoonLock Banner
Ray Fernandez

Ray Fernandez

Ray has been covering tech and cybersecurity for over 15 years. His work has appeared on TechRepublic, VentureBeat, Forbes, Entrepreneur, and the Microsoft Blog, among others.