{"id":52682,"date":"2026-07-22T16:34:18","date_gmt":"2026-07-22T20:34:18","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=52682"},"modified":"2026-07-22T16:34:18","modified_gmt":"2026-07-22T20:34:18","slug":"crashstealer","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2026\/07\/22\/crashstealer\/","title":{"rendered":"CrashStealer"},"content":{"rendered":"<p><a href=\"https:\/\/www.jamf.com\/blog\/crashstealer-macos-infostealer-analysis\/\">Thijs Xhaflaire<\/a> (via <a href=\"https:\/\/www.macintouch.com\/posts\/52518\">Ric Ford<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.jamf.com\/blog\/crashstealer-macos-infostealer-analysis\/\">\n<p>Jamf Threat Labs discovers and investigates CrashStealer, a C++ macOS infostealer that impersonates Apple's crash-reporting framework to harvest browser credentials, cryptocurrency wallets and keychain data, encrypting stolen files with AES-GCM before exfiltrating them to a remote command-and-control server.<\/p>\n<p>[&#8230;]<\/p>\n<p>Unlike the payload it eventually installs, the dropper is properly code signed and notarized: it is a universal (arm64 and x86_64) binary signed with the Developer ID <code>Emil Grigorov (WWB7JA7AQV)<\/code>, has hardened runtime enabled, and carries a stapled notarization ticket. Notably, the disk image itself is signed as well, not just the application inside it, which is uncommon in malicious DMG delivery where the container is typically left unsigned.<\/p>\n<p>[&#8230;]<\/p>\n<p>That file supplies the <code>curl<\/code> command the dropper runs next. Staging the first hop on a trusted developer domain keeps the initial network activity inconspicuous.<\/p>\n<p>[&#8230;]<\/p>\n<p>[The script] clears extended attributes on the staged bundle with <code>xattr -cr<\/code>, makes the inner binary executable, strips the payload's existing signature and re-signs it ad-hoc (<code>codesign --remove-signature<\/code> followed by <code>codesign -s - --force --deep --no-strict<\/code>), registers it with Launch Services via <code>lsregister -f<\/code>, and finally launches it in the background with <code>open -g -n<\/code>.<\/p>\n<\/blockquote>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2025\/12\/23\/notarized-mac-app-that-downloads-malware\/\">Notarized Mac App That Downloads Malware<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2025\/09\/08\/fake-mac-apps-on-github\/\">Fake Mac Apps on GitHub<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2025\/07\/17\/notarized-atomic-stealer-amos\/\">Notarized Atomic Stealer (AMOS)<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2020\/10\/30\/more-notarized-mac-malware\/\">More Notarized Mac Malware<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2015\/07\/17\/app-transport-security\/\">App Transport Security<\/a><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Thijs Xhaflaire (via Ric Ford): Jamf Threat Labs discovers and investigates CrashStealer, a C++ macOS infostealer that impersonates Apple's crash-reporting framework to harvest browser credentials, cryptocurrency wallets and keychain data, encrypting stolen files with AES-GCM before exfiltrating them to a remote command-and-control server. [&#8230;] Unlike the payload it eventually installs, the dropper is properly code [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2026-07-22T20:34:21Z","apple_news_api_id":"acf4a6cd-afaf-4b1e-805a-67748295d3e7","apple_news_api_modified_at":"2026-07-22T20:34:21Z","apple_news_api_revision":"AAAAAAAAAAD\/\/\/\/\/\/\/\/\/\/w==","apple_news_api_share_url":"https:\/\/apple.news\/ArPSmza-vSx6AWmd0gpXT5w","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[466,2479,465,30,2742,504,1842,48],"class_list":["post-52682","post","type-post","status-publish","format-standard","hentry","category-technology","tag-codesigning","tag-crash-reporter","tag-gatekeeper","tag-mac","tag-macos-tahoe-26","tag-malware","tag-notarization","tag-security"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/52682","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=52682"}],"version-history":[{"count":1,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/52682\/revisions"}],"predecessor-version":[{"id":52683,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/52682\/revisions\/52683"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=52682"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=52682"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=52682"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}