ZDNET58%

New Mac malware masquerades as Apple's crash reporter: 3 ways to dodge the threat 35%

By Charlie Osborne45%

7/15/2026, 5:18:35 PM

BS Summary: This article contains 28 faulty reasoning types, including Loss Aversion, Ambiguity (Equivocation), and Indoctrination, with Hasty Generalization as the most egregious example at 17% saturation with 137 hits. Analysis detected 1,408 faulty-reasoning hits from 805 analyzed words, generating a BS Score of 42.6% and a BS Rank of 35% (14,270 of 21,886 articles). This article is better (less manipulative) than 65.20% of the article peer group.

Follow ZDNET: Add us as a preferred source on Google. 
ZDNET's key takeaways 
New MacOS malware masquerades as Apple's crash reporter. 
CrashStealer was just released into the wild. 
Adopt these habits to protect yourself and your Mac from infection. 
A new form of malware is masquerading as Apple's crash reporting tool to target MacOS users and harvest their data, account credentials, keychain entries, and cryptocurrency wallets. 
Also: Why this fully agentic ransomware attack is giving researchers nightmares 
In a July 13 research advisory, Jamf cybersecurity researchers said the malware, dubbed "CrashStealer," is a C++ infostealer that first appeared on their radar following a suspicious upload to VirusTotal. 
It appears that the malware was in development around May but has now been released into the wild. 
The CrashStealer attack and what to look out for 
You've probably encountered Apple's legitimate crash reporting tool, which appears when software crashes or quits unexpectedly -- a pop-up window asks whether you want to report the error. 
When the malware lands on a MacOS machine, it impersonates Apple's crash reporter by using the aliases CrashReporter.dmg (for installation), CrashReporter.app (for the application bundle), and a legitimate-looking icon. 
Also: These two critical Mac security features are off by default - how to turn them on and why you should 
While this malware contains many of the basic info-stealing capabilities you would expect, it also has an interesting prompt. 
CrashReporter tries to unlock the keychain by displaying a fake password prompt that mimics a genuine MacOS authorization request. 
The malware then validates these stolen credentials locally before targeting installed password managers, browsers, and cryptocurrency wallets. 
Passwords are then whisked off in an encrypted package to an attacker-controlled server. 
How infostealers actually land on your Mac 
Some infostealers, such as CrashStealer, arrive on your Mac as disk images. 
Disk images, which end in .dmg, are the standard way to install software on a Mac -- you click them, drag them to the Applications folder, and begin the installation process. 
What makes this case interesting is that CrashStealer's main .dmg file, distributed as "Werkbit Setup" -- which packages up CrashReporter.dmg -- is a signed and Apple-notarized dropper disguised as a disk image. 
"Because the dropper carries a valid Developer ID and a stapled notarization ticket, it clears Gatekeeper on first launch, in contrast to the ad-hoc-signed payload it installs," the researchers note. 
In other words, the .dmg file appears to be a legitimate, trustworthy utility, and there are no immediate red flags. 
Another major attack vector for MacOS is ClickFix. 
This technique relies on social engineering to lure a user into entering and executing a command prompt themselves, often with copy-and-paste instructions to "fix" an issue on their PC or to resolve a CAPTCHA. 
Yet another angle is AI. 
As described by Huntress researchers, Atomic MacOS Stealer is being distributed through poisoned AI chatbot conversations that lead unwitting victims to malicious websites and payloads. 
The three habits that block most of them 
Remember when we considered MacOS, and Apple machines in general, impervious to most forms of malware? 
This was even part of Apple's own marketing campaigns. 
That's now far from the truth. 
We also need to consider the impact that AI is having on the cybercriminal world. 
AI is being abused to write malicious code, to improve phishing emails and campaigns, and was recently discovered as the backbone of a fully agentic ransomware attack chain. 
It might be a matter of months or only a few short years before the traditional MacOS attack vectors are replaced by AI-related threats. 
Also: The best malware removal software: Expert tested and reviewed 
However, for now, there are three habits you can adopt to steer clear of threats like CrashStealer: 
Always check a .dmg source. 
You can't really know what's in a .dmg package from the surface, and if you are downloading cracked or pirated software, you are at high risk of running malware on your own machine. 
Verify password requests. 
Gatekeeper prompts and warnings exist for a good reason, and so these should not be ignored. 
If you encounter a pop-up or alert on your Mac that you didn't expect, be cautious about submitting your password. 
For example, if you've opened your VPN app and it needs an update, that might require your password. 
But if you're casually browsing and an unknown system process requests the same, this could be a sign of infection. 
Keep your MacOS system updated. 
Many of us are guilty of this -- we don't want an update to interrupt our daily routine, work, or entertainment, and so we ignore OS prompts and App Store update notifications. 
However, these updates often include bug fixes and upgrades that strengthen our security, protecting not only our machines but also our data. 
Article reasoning-pattern comparisonThis article: 3.4%Charlie Osborne: 1.9%ZDNET: 2.9%Confirmation Bias3.4%This article: 3.9%Charlie Osborne: 0.6%ZDNET: 1.7%Anchoring Bias3.9%This article: 9.8%Charlie Osborne: 5.9%ZDNET: 3.1%Availability Heuristic9.8%This article: 6.3%Charlie Osborne: 1.1%ZDNET: 1.0%Representativeness Heuristic6.3%This article: 0.0%Charlie Osborne: 0.2%ZDNET: 0.5%Hindsight Bias0.0%This article: 1.0%Charlie Osborne: 1.1%ZDNET: 3.2%Overconfidence Bias1.0%This article: 3.6%Charlie Osborne: 3.9%ZDNET: 4.2%Framing Effect3.6%This article: 13.3%Charlie Osborne: 3.8%ZDNET: 1.4%Loss Aversion13.3%This article: 8.6%Charlie Osborne: 1.5%ZDNET: 0.7%Status Quo Bias8.6%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.2%Sunk Cost Effect0.0%This article: 5.7%Charlie Osborne: 1.9%ZDNET: 5.2%Optimism Bias5.7%This article: 4.6%Charlie Osborne: 3.3%ZDNET: 1.3%Pessimism Bias4.6%This article: 8.9%Charlie Osborne: 8.4%ZDNET: 4.5%Negativity Bias8.9%This article: 4.0%Charlie Osborne: 0.3%ZDNET: 1.6%Self-Serving Bias4.0%This article: 0.0%Charlie Osborne: 0.7%ZDNET: 0.3%Fundamental Attribution Error0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.1%Actor-Observer Bias0.0%This article: 0.0%Charlie Osborne: 0.3%ZDNET: 0.5%In-Group Bias0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.2%Out-Group Homogeneity Bias0.0%This article: 4.0%Charlie Osborne: 2.0%ZDNET: 3.9%Halo Effect4.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.2%Horn Effect0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.0%Dunning-Kruger Effect0.0%This article: 6.6%Charlie Osborne: 2.4%ZDNET: 1.5%Recency Bias6.6%This article: 2.0%Charlie Osborne: 0.4%ZDNET: 0.4%Primacy Effect2.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.1%Blind-Spot Bias0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.0%Ad Hominem0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.1%Straw Man0.0%This article: 11.8%Charlie Osborne: 4.4%ZDNET: 4.7%Appeal to Authority11.8%This article: 0.6%Charlie Osborne: 0.9%ZDNET: 1.5%False Dilemma0.6%This article: 3.0%Charlie Osborne: 1.8%ZDNET: 0.6%Slippery Slope3.0%This article: 0.0%Charlie Osborne: 0.3%ZDNET: 0.2%Circular Reasoning0.0%This article: 17.0%Charlie Osborne: 3.5%ZDNET: 6.5%Hasty Generalization17.0%This article: 0.0%Charlie Osborne: 0.6%ZDNET: 0.5%Red Herring0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.5%Bandwagon0.0%This article: 10.7%Charlie Osborne: 4.1%ZDNET: 2.0%Appeal to Emotion10.7%This article: 2.0%Charlie Osborne: 0.1%ZDNET: 0.7%Begging the Question2.0%This article: 4.6%Charlie Osborne: 1.0%ZDNET: 1.5%Post Hoc (False Cause)4.6%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.0%Tu Quoque0.0%This article: 0.0%Charlie Osborne: 0.6%ZDNET: 0.2%Burden of Proof0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.1%Appeal to Nature0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.3%Composition/Division0.0%This article: 6.2%Charlie Osborne: 1.7%ZDNET: 4.9%Anecdotal6.2%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.1%No True Scotsman0.0%This article: 12.9%Charlie Osborne: 2.1%ZDNET: 2.5%Ambiguity (Equivocation)12.9%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.0%Gambler’s Fallacy0.0%This article: 0.0%Charlie Osborne: 0.2%ZDNET: 0.2%Middle Ground0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.1%Personal Incredulity0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.2%Special Pleading0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.1%Genetic Fallacy0.0%This article: 3.7%Charlie Osborne: 2.4%ZDNET: 0.9%Unattributed Quote3.7%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.5%Quote-first Misdirection0.0%This article: 2.1%Charlie Osborne: 3.0%ZDNET: 6.8%Biased Writer Voice2.1%This article: 12.2%Charlie Osborne: 11.1%ZDNET: 3.9%Indoctrination12.2%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.0%Politically Right Leaning Bias0.0%This article: 2.5%Charlie Osborne: 1.9%ZDNET: 7.5%Attempt to Sell a Product or S…2.5%

805 words analyzed.

Speakers

3speakers12%attributed speech707writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 14 words • 100.0% coverageZDNET • 10 words • 100.0% coverageZDNET • 3 words • 100.0% coverageWriter's voice • 8 words • 0.0% coverageWriter's voice • 7 words • 0.0% coverageWriter's voice • 11 words • 100.0% coverageWriter's voice • 27 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageJamf • 30 words • 0.0% coverageWriter's voice • 18 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 28 words • 0.0% coverageWriter's voice • 29 words • 0.0% coverageWriter's voice • 21 words • 100.0% coverageWriter's voice • 19 words • 0.0% coverageWriter's voice • 19 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageWriter's voice • 7 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 31 words • 0.0% coverageWriter's voice • 32 words • 0.0% coverageJamf • 30 words • 100.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageWriter's voice • 34 words • 0.0% coverageWriter's voice • 5 words • 0.0% coverageHuntress • 25 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageWriter's voice • 16 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 6 words • 0.0% coverageWriter's voice • 15 words • 0.0% coverageWriter's voice • 28 words • 0.0% coverageWriter's voice • 24 words • 0.0% coverageWriter's voice • 10 words • 100.0% coverageWriter's voice • 17 words • 100.0% coverageWriter's voice • 5 words • 100.0% coverageWriter's voice • 33 words • 0.0% coverageWriter's voice • 3 words • 100.0% coverageWriter's voice • 16 words • 100.0% coverageWriter's voice • 20 words • 100.0% coverageWriter's voice • 18 words • 0.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 5 words • 100.0% coverageWriter's voice • 32 words • 0.0% coverageWriter's voice • 22 words • 0.0% coverage
Selected voice

Jamf

100%flagged-word coverage
60 attributed words61% of attributed speech84% writer coverage
0%25.0%50.0%Unattributed Quote+50.0 ptsWriter: 0.0%Jamf: 50.0%50.0%Indoctrination-13.9 ptsWriter: 13.9%Jamf: 0.0%0.0%Biased Writer Voice-2.0 ptsWriter: 2.0%Jamf: 0.0%0.0%Attempt to Sell a Product -1.4 ptsWriter: 1.4%Jamf: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.