macOS Malware Installs Fake Google Software Update LaunchAgent for Persistence
ID: 93ac4e9d-ecf8-518a-b7f1-825b36af5e67
STIX ID: report--93ac4e9d-ecf8-518a-b7f1-825b36af5e67
Feed Name: cybersecurityNews.com
Reaper is a sophisticated macOS infostealer (SHub family) that lures victims with fake WeChat/Miro installers from a typo-squatted Microsoft domain, executes in-memory payloads via AppleScript/Script Editor to evade mitigations, and establishes persistence by mimicking Google’s Keystone update service with a LaunchAgent; it steals documents, crypto wallet files, browser credentials, and exfiltrates staged data to C2 endpoints while employing anti-analysis checks and obfuscation—SentinelOne provides IoCs and detection/remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
