New macOS malware steals passwords by posing as Apple’s crash-reporting tool
2026-07-14T14:51:48Z•74aa91fea54952f2d3de9fae275ad9b8fd67564a54301fa26e6a4429179d2629
AI securityCrashStealerFIDO2GCPWKeychainMicrosoft EntraNCA charges','IoT','smart-home researchRussian ComsSANS surveySecure BootTracebitUEFIauthenticationcaller ID spoofingcardingcredential theftcryptocurrency walletsdefensive canariesfraudinfostealermacOSpasskeysprompt injectionshim bypassunderground forums
What happened
Multiple security developments: Jamf Threat Labs identified a new macOS infostealer dubbed “CrashStealer” that impersonates Apple’s crash-reporting tool to exfiltrate passwords, Keychain data, and cryptocurrency wallets; it was first seen in May and detected in the wild by July 2026. ESET found legacy signed UEFI shims (versions ≤0.9) that can bypass Secure Boot; Microsoft revoked the affected shims. Google began rolling out FIDO2 hardware key and phone passkey support for Windows login via Google Credential Provider for Windows (GCPW), and Microsoft announced Entra ID will default to passkeys
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- 74aa91fea54952f2d3de9fae275ad9b8fd67564a54301fa26e6a4429179d2629
- Enrichment time
- 2026-07-14T14:51:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.