New Malware Threat Targeting Apple Devices Exploits Apple Notarization

Mac users are being targeted by a new form of malware that impersonates Apple's built-in crash reporting feature.

This new malware, CrashStealer, is a macOS infostealer that harvests login details, cryptocurrency wallets, and any other account data stored on the system or in browsers.

CrashStealer is delivered through a disk image that imitates Apple's crash reporting component. Its aim is to trick users into installing the password stealing payload.

Its initial attack chain was unclear at first. However, some researchers traced one of the websites users visited, finding it posed as a legitimate platform to distribute the video conference tool Werkbit. Before downloading off the website, certain users are given a special meeting PIN. How victims are selected to get this PIN remains unknown.

The second stage of the attack involves the user being directed to a signed and Apple notarized dropper, distributed as a "Werkbit Setup" disk image. This disk image is signed with a valid Apple developer ID and a notarization ticket. This allows it to use the macOS security feature, Apple Gatekeeper, which is designed to prevent malware execution.

The user is then encouraged to run an application which is designed to look exactly like a legitimate software installer. Once installed, the application reaches out to a GitHub API which decodes a jumbled script, that decoded script becomes a downloader-installer that then gets the CrashStealer payload.

Once the infostealer is on the device, it displays a password prompt designed to resemble an actual macOS authorization request. Once the device's system login credentials are confirmed, the infostealer begins its objective: stealing usernames, passwords, password manager logins, cryptocurrency wallets, any credentials stored on the device, and any other keychain data that provides account access.

Source: https://www.infosecurity-magazine.com/news/macos-malware-apple-crash-reporter/; https://www.kaspersky.com/blog/crashstealer-werkbit-macos-infostealer/56217/

Commentary

The most important part of this infostealer is not exactly what it steals, but rather how it is built.

The presence of a developer ID shows that the application was signed by a developer who purchased a signing certificate, using that to cryptographically sign the malicious application. These steps make the application appear more legitimate.

Infostealers commonly skip this step. It requires purchasing a certificate and requires submitting the app to Apple's notarization servers. Many do not bother to do so.

The benefit of going through this process for cybercriminals is fewer security prompts when the victim attempts to open the application.

The infostealer further evades detection by impersonating Apple's built-in crash reporter.

Organizations utilizing Apple devices should ensure their staff is aware of this new malware threat and are prepared with strong cybersecurity training.

One of the most important things organizations can do to prevent against this threat is to carefully research and verify apps before installing them. This includes primarily using utilities/apps from official app stores whenever possible.

The final takeaway is that organizations using Apple devices should keep up to date regarding this new malware threat.

Finally, your opinion is important to us. Please complete the opinion survey:

Product

Articles

Ignoring Pay Disparity Claims: A Risky Strategy For Healthcare Employers

The EEOC sued a healthcare employer and alleged a female employee was paid far less than her male coworker. We discuss.

Why Relying On Restitution Is Not A Good Bet

A tribal organization suffered a loss of nearly $5M after an employee's embezzlement scheme. We discuss why restitution does not always equal full recovery.

Staffing Shortage Is No Defense To PUMP Charges

A medical center was investigated by the U.S. Department of Labor after allegations of failing to allow breast milk pump breaks for nursing workers in violation of the PUMP Act. We examine why staffing shortages do not dictate breaks.

The Multi-Step Process For Healthcare Employers When Evaluating Accommodation Requests

A healthcare employer's leave policies lead to a sizeable disability discrimination settlement with the EEOC. Learn more about this case and about the difficulty of proving undue hardship.

One Controller, Higher Threat: The Embezzlement Risk Of Too Much Control

A controller of a small family textile company in California pled guilty and was sentenced to eight years in prison for embezzling more than $3.2M. We comment on the internal controls that can help employers lower their risk.