CrashStealer: macOS malware uses notarized dropper to evade Gatekeeper

Learn how CrashStealer, a new malware for macOS, uses a notarized dropper to evade Gatekeeper and steal passwords and sensitive data. Protect yourself!

lunes, 13 de julio de 2026 • 4 min read • Q2BSTUDIO Team

CrashStealer: Native C++ Data Stealing on macOS

In today's cybersecurity landscape, the emergence of new threats targeting the macOS ecosystem has become a constant concern for businesses and professionals. Recently, researchers have identified a particularly concerning variant: CrashStealer, a malware designed to steal sensitive information that uses a notarized dropper to evade Gatekeeper's protections. This finding not only highlights the growing sophistication of cybercriminals, but also underscores the need for more robust and personalized defense strategies.

CrashStealer distinguishes itself from other common information stealers by its implementation in native C++, allowing it to be more efficient and difficult to detect. Unlike typical droppers based on AppleScript or Objective-C wrappers, this malware locally verifies the victim's login password before proceeding with data exfiltration. This feature indicates a meticulous approach on the part of the attackers, who seek to ensure that the system is indeed compromised before activating the malicious payload. The use of a notarized dropper – that is, digitally signed and approved by Apple – represents a qualitative leap in evasion techniques, since Gatekeeper relies on these seals to allow the software to run. Thus, the malware manages to circumvent one of the main security mechanisms of the operating system.

For organizations that rely on macOS environments, these types of threats require a thorough review of their cybersecurity policies. It's not enough to rely solely on the system's native protections; Advanced detection and response solutions and specialized services to identify anomalous behavior are essential. In this context, the cybersecurity and pentesting services offered by Q2BSTUDIO become a fundamental ally. Through custom security audits and penetration testing, it is possible to detect vulnerabilities that could be exploited by malware such as CrashStealer, and establish effective barriers before a data breach occurs.

Beyond reacting to specific threats, prevention remains the most cost-effective strategy. Deploying bespoke applications that integrate security controls by design—following Secure SDLC principles—dramatically reduces the attack surface. Q2BSTUDIO specializes in custom software development that not only meets functional needs, but also incorporates layers of protection tailored to each customer's risk profile. This is especially relevant when handling sensitive data or operating in regulated sectors, where a security incident can lead to financial penalties and severe reputational damage.

Artificial intelligence is also marking a before and after in the fight against malware. AI-based systems can analyze behavior patterns in real-time, identify suspicious deviations, and block malicious processes before they achieve their goal. In the case of CrashStealer, where password verification reveals specific behavior, machine learning models trained to recognize unusual scripts could quickly alert security teams. Enterprise AIs developed by Q2BSTUDIO allow these capabilities to be natively integrated into corporate workflows, empowering early detection without slowing down operations.

Another critical front is the management of cloud infrastructure. Since many macOS environments today integrate with cloud services for storage, synchronization, and backups, attackers can use compromised access to move laterally to platforms such as AWS or Azure. That's why having AWS and Azure cloud services that include advanced security configurations—such as encryption, network segmentation, and continuous monitoring—is essential. Q2BSTUDIO offers consulting and management of cloud infrastructures, ensuring that hybrid or multicloud environments maintain a level of protection consistent with current threats.

Visibility into what's happening on endpoints and in the cloud is just as important as the defense tools themselves. This is where business intelligence services and tools like power bi come into play, allowing organizations to consolidate security data from different sources (system logs, EDR alerts, network events) into interactive dashboards. With these dashboards, analysts can identify trends, correlate incidents, and make informed decisions quickly. Q2BSTUDIO helps to design and implement these Business Intelligence solutions, adapting them to the specific needs of each company.

We cannot forget the potential of AI agents in automating incident responses. Imagine an intelligent agent that, upon detecting behavior similar to CrashStealer (e.g., a process that validates passwords repeatedly), automatically isolates the affected computer, notifies the security team, and generates a preliminary forensic report. This ability to react immediately reduces exposure time and limits damage. At Q2BSTUDIO we develop custom AI agents that integrate with existing security platforms, elevating the cyber maturity of organizations.

All in all, CrashStealer is yet another warning that security in macOS is no longer a minor issue. Combining a notarized dropper with local credential verification techniques demands equally sophisticated answers. Enterprises must take a holistic approach that combines proactive cybersecurity, tailored software with built-in defenses, artificial intelligence for advanced detection, secure AWS and Azure cloud services, and business intelligence to maintain visibility. Q2BSTUDIO, as a technology partner, offers solutions on all of these fronts, helping organizations stay ahead of threats and protect their most valuable asset: information.

If you want to learn more about how to strengthen your security posture against malware such as CrashStealer, we invite you to learn about our specialized cybersecurity and pentesting services, where we combine technical expertise and updated methodologies to ensure an effective defense.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.