Skip to content
Jamf Threat Labs releases analysis of macOS info stealer dubbed 'CrashStealer'

Jamf Threat Labs releases analysis of macOS info stealer dubbed 'CrashStealer'

Mactech July 13, 2026

Jamf Threat Labs has released its analysis of a previously undocumented macOS infostealer, dubbed “CrashStealer.”

Written in native C++, the malware was detected in the wild in early July with the goal of harvesting data across browsers, cryptocurrency wallets, password managers, and more.

CrashStealer is delivered through a disk image that impersonates Apple’s built-in crash-reporting component, aiming to deceive victims through just a slight alteration in the impersonating application’s name.

I hope you’ll help support Apple World Today by becoming a patron. Almost all our income is from Patreon support and posts. Patreon pricing ranges from $2 to $10 a month. Thanks in advance for your support.

Extracted Entities

Attack Types (1)

Malware (1)

MITRE ATT&CK (1)

Platforms (1)