Hackers Use Fake CleanMyMac Site to Deploy SHub Stealer and Hijack Crypto Wallets
ID: 8a1a74a1-35ec-584b-af94-de05bc086229
STIX ID: report--8a1a74a1-35ec-584b-af94-de05bc086229
Feed Name: cybersecurityNews.com
Malwarebytes researchers found a fake CleanMyMac site (cleanmymacos.org) distributing SHub Stealer via a ClickFix terminal command; SHub harvests credentials, Keychain data, browser and Telegram data, and backdoors Electron-based crypto wallets (Exodus, Atomic Wallet, Ledger Wallet/Live, Trezor Suite) by replacing app.asar and re-signing apps to silently exfiltrate seed phrases to wallets-gate.io, uses geofencing to avoid Russian-language keyboards, maintains persistence via a LaunchAgent impersonating Google Keystone, and communicates with C2 at res2erch-sl0ut.com.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
