CrashStealer Malware Poses As Apple Crash Reporter To Hijack Macs

https://hothardware.com/contentimages/NewsItem/71117/content/16x9_2133x1200_highres-macos-crashstealer-malware-news.jpg

Many Mac users believe that they don’t need to worry about security because macOS is more secure and a smaller platform that isn’t worth targeting, but that’s just not true. A new piece of malware, dubbed CrashStealer, was discovered by the researchers at Jamf Threat Labs and it has proven to be a cut above most commodity malware.

CrashStealer is capable of skirting past macOS security features. To get past the macOS Gatekeeper, the dropper carries a valid developer ID in addition to a notarization ticket that enables it to launch without raising any security flags. The dropper then signs the payload, which is downloaded from the attacker’s infrastructure, to continue bypassing security checks.

It also goes to great lengths to deceive users during its installation too. Its install flow mirrors that of a legitimate application, including well designed graphics and step-by-step instructions on how to properly install...

Copyright of this story solely belongs to hothardware.com. To see the full text click HERE

Read more