logo

Hackers Use Fake CleanMyMac Site to Deploy SHub Stealer and Hijack Crypto Wallets

ID: 8a1a74a1-35ec-584b-af94-de05bc086229

STIX ID: report--8a1a74a1-35ec-584b-af94-de05bc086229

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-03-09

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Malwarebytes researchers found a fake CleanMyMac site (cleanmymacos.org) distributing SHub Stealer via a ClickFix terminal command; SHub harvests credentials, Keychain data, browser and Telegram data, and backdoors Electron-based crypto wallets (Exodus, Atomic Wallet, Ledger Wallet/Live, Trezor Suite) by replacing app.asar and re-signing apps to silently exfiltrate seed phrases to wallets-gate.io, uses geofencing to avoid Russian-language keyboards, maintains persistence via a LaunchAgent impersonating Google Keystone, and communicates with C2 at res2erch-sl0ut.com.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.