Reaper Splits Trust Across Microsoft, Apple, and Google

Reaper breaks the normal macOS trust model by spreading its disguise across the chain. One vendor whitelist or mitigation is not enough when hosting, execution, and persistence each pretend to belong to a different trusted brand. SentinelOne says the new SHub variant uses fake WeChat and Miro lures, a typo-squatted Microsoft domain for hosting, Apple-themed execution to bypass Terminal mitigation, and a fake Google Software Update directory for persistence. It also adds chunked document theft and keeps the same credential-stealing role seen in earlier SHub builds. That mix turns a stealer into a longer-lived intrusion path. Even if the initial run is blocked, the staged branding split lets the malware keep reaching for credentials and documents under trusted names.

Part of the PlainSec briefing for 2026-05-20

Sources