Malware · 134 giorni fa
Reaper rompe il normale modello di fiducia di macOS distribuendo il proprio travestimento lungo la catena. Una whitelist o una mitigazione di un solo vendor non è sufficiente quando hosting, esecuzione e persistenza fingono ciascuno di appartenere a un brand fidato diverso.
4 fonti che coprono questa storia
Stealer Spoofs Google, Microsoft & Apple, Then Backdoors macOS
SHub Reaper stealer, which hides behind fake WeChat and Miro installers, marks a shift from ClickFix social engineering to Apple script-based execution.
A new SHub Reaper macOS infostealer uses fake Apple, Google, and Microsoft branding to steal credentials and target crypto wallets.
SHub macOS infostealer variant spoofs Apple security updates
A new variant of the 'SHub' macOS infostealer uses AppleScript to show a fake security update message and installs a backdoor.
SHub Reaper | macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain
SHub Reaper bypasses Apple's Terminal mitigation, steals credentials and documents, and plants a persistent backdoor for continued access after infection.
Part of the PlainSec briefing for 2026-05-20