Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
YouTube Security VideosNeil Patel: Steal What Your Competitors Test #shorts(19.09.2026 um 20:04 Uhr)
Sichere ProgrammierungI wrote down the pass mark before the test. Then I failed it.(19.09.2026 um 19:43 Uhr)
Sichere ProgrammierungYour agent waits a full second to send the number 3(19.09.2026 um 20:19 Uhr)
Sichere ProgrammierungReading a 1.2 Million PaperCut Fingerprint Count Correctly(19.09.2026 um 20:20 Uhr)
Sichere Programmierung2. Linux Commands - Beginner(19.09.2026 um 20:20 Uhr)
KI & AI VideosJulian Goldie SEO: NEW Google Updates are Crazy Good! 🤯(19.09.2026 um 20:00 Uhr)
YouTube Security VideosNeil Patel: Steal What Your Competitors Test #shorts(19.09.2026 um 20:04 Uhr)
Sichere ProgrammierungI wrote down the pass mark before the test. Then I failed it.(19.09.2026 um 19:43 Uhr)
Sichere ProgrammierungYour agent waits a full second to send the number 3(19.09.2026 um 20:19 Uhr)
Sichere ProgrammierungReading a 1.2 Million PaperCut Fingerprint Count Correctly(19.09.2026 um 20:20 Uhr)
Sichere Programmierung2. Linux Commands - Beginner(19.09.2026 um 20:20 Uhr)
KI & AI VideosJulian Goldie SEO: NEW Google Updates are Crazy Good! 🤯(19.09.2026 um 20:00 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

CrashStealer Malware Targets Mac Users Through Fake App Prompts

Security researchers have uncovered a new threat targeting Mac computers. A malicious program called "CrashStealer" is currently circulating online, and it is designed to look like a legitimate system tool to trick users into handing over their passwords. The malware is focused on stealing browser data, crypto wallet credentials, and passwords saved directly on your computer. What makes this attack especially dangerous is that the initial download actually passed security checks from Apple and received official notarization. Apple has since revoked the developer credentials, but the campaign highlights how attackers are getting better at sneaking past standard security gates. Attackers use a fake meeting app to deliver the payload The attack typically starts with a fake collaboration or meeting app called "Werkbit." Scammers place this download behind a specific meeting PIN, meaning they are likely targeting specific victims directly rather than blasting the link across the public internet. Once a user downloads and opens the Werkbit app, it quietly reaches out to a remote server and downloads the actual CrashStealer malware in the background. The malware then disguises itself as "CrashReporter," a name chosen to mimic an official macOS crash reporting tool that most users would ignore. The malware uses fake password prompts to unlock your data Once installed on your system, CrashStealer generates a pop-up window that looks exactly like a standard Mac authorization prompt. It asks you to enter your system password to grant access for "system administration." If you enter your password, the malware validates it immediately. It then uses your confirmed password to unlock your Mac login keychain. CrashStealer rapidly copies your saved passwords from browsers, password managers, and crypto extensions. It bundles all this data into an encrypted ZIP file and sends it back to the attackers. The malware also sets itself to run automatically every time you log in, so the threat stays active even if you restart your computer. If you suspect you have downloaded a suspicious meeting app or entered your password into an unexpected prompt, security experts recommend disconnecting from the internet, changing all major passwords from a safe device, and completely erasing your Mac to perform a clean install.
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten CrashStealer Malware Targets Mac Users Through Fake App Prompts

Thematisch verwandte Begriffe: CrashStealer, Malware, Targets, Users · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-61591 | djust provides Phoenix LiveView-style reactive server-side rendering for…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick