Mac users are being targeted by a new form of malware that impersonates Apple's built-in crash reporting feature.
This new malware, CrashStealer, is a macOS infostealer that harvests login details, cryptocurrency wallets, and any other account data stored on the system or in browsers.
CrashStealer is delivered through a disk image that imitates Apple's crash reporting component. Its aim is to trick users into installing the password stealing payload.
Its initial attack chain was unclear at first. However, some researchers traced one of the websites users visited, finding it posed as a legitimate platform to distribute the video conference tool Werkbit. Before downloading off the website, certain users are given a special meeting PIN. How victims are selected to get this PIN remains unknown.
The second stage of the attack involves the user being directed to a signed and Apple notarized dropper, distributed as a "Werkbit Setup" disk image. This disk image is signed with a valid Apple developer ID and a notarization ticket. This allows it to use the macOS security feature, Apple Gatekeeper, which is designed to prevent malware execution.
The user is then encouraged to run an application which is designed to look exactly like a legitimate software installer. Once installed, the application reaches out to a GitHub API which decodes a jumbled script, that decoded script becomes a downloader-installer that then gets the CrashStealer payload.
Once the infostealer is on the device, it displays a password prompt designed to resemble an actual macOS authorization request. Once the device's system login credentials are confirmed, the infostealer begins its objective: stealing usernames, passwords, password manager logins, cryptocurrency wallets, any credentials stored on the device, and any other keychain data that provides account access.
Source: https://www.infosecurity-magazine.com/news/macos-malware-apple-crash-reporter/; https://www.kaspersky.com/blog/crashstealer-werkbit-macos-infostealer/56217/
Commentary
The most important part of this infostealer is not exactly what it steals, but rather how it is built.
The presence of a developer ID shows that the application was signed by a developer who purchased a signing certificate, using that to cryptographically sign the malicious application. These steps make the application appear more legitimate.
Infostealers commonly skip this step. It requires purchasing a certificate and requires submitting the app to Apple's notarization servers. Many do not bother to do so.
The benefit of going through this process for cybercriminals is fewer security prompts when the victim attempts to open the application.
The infostealer further evades detection by impersonating Apple's built-in crash reporter.
Organizations utilizing Apple devices should ensure their staff is aware of this new malware threat and are prepared with strong cybersecurity training.
One of the most important things organizations can do to prevent against this threat is to carefully research and verify apps before installing them. This includes primarily using utilities/apps from official app stores whenever possible.
The final takeaway is that organizations using Apple devices should keep up to date regarding this new malware threat.
