New macOS malware steals passwords by posing as Apple’s crash-reporting tool

2026-07-14T14:51:48Z74aa91fea54952f2d3de9fae275ad9b8fd67564a54301fa26e6a4429179d2629
AI securityCrashStealerFIDO2GCPWKeychainMicrosoft EntraNCA charges','IoT','smart-home researchRussian ComsSANS surveySecure BootTracebitUEFIauthenticationcaller ID spoofingcardingcredential theftcryptocurrency walletsdefensive canariesfraudinfostealermacOSpasskeysprompt injectionshim bypassunderground forums

What happened

Multiple security developments: Jamf Threat Labs identified a new macOS infostealer dubbed “CrashStealer” that impersonates Apple’s crash-reporting tool to exfiltrate passwords, Keychain data, and cryptocurrency wallets; it was first seen in May and detected in the wild by July 2026. ESET found legacy signed UEFI shims (versions ≤0.9) that can bypass Secure Boot; Microsoft revoked the affected shims. Google began rolling out FIDO2 hardware key and phone passkey support for Windows login via Google Credential Provider for Windows (GCPW), and Microsoft announced Entra ID will default to passkeys

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
74aa91fea54952f2d3de9fae275ad9b8fd67564a54301fa26e6a4429179d2629
Enrichment time
2026-07-14T14:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.