logo

macOS Malware Installs Fake Google Software Update LaunchAgent for Persistence

ID: 93ac4e9d-ecf8-518a-b7f1-825b36af5e67

STIX ID: report--93ac4e9d-ecf8-518a-b7f1-825b36af5e67

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2026-05-19

Date Updated: 2026-05-20

Author: Tushar Subhra Dutta

...
...

Reaper is a sophisticated macOS infostealer (SHub family) that lures victims with fake WeChat/Miro installers from a typo-squatted Microsoft domain, executes in-memory payloads via AppleScript/Script Editor to evade mitigations, and establishes persistence by mimicking Google’s Keystone update service with a LaunchAgent; it steals documents, crypto wallet files, browser credentials, and exfiltrates staged data to C2 endpoints while employing anti-analysis checks and obfuscation—SentinelOne provides IoCs and detection/remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.