logo

Fake Google Software Update Used by macOS Malware For Persistence

ID: 35b9044a-7e36-5ca8-9a3a-59e952dc9b3c

STIX ID: report--35b9044a-7e36-5ca8-9a3a-59e952dc9b3c

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Varshini

...
...

Reaper is a newly observed macOS information-stealing malware that lures victims via typo-squatted fake download pages, fingerprints visitors to avoid analysis, and uses AppleScript to harvest credentials, browsers, keychain data, files, and cryptocurrency wallets; it also installs a persistent backdoor masquerading as Google Software Update and contacts C2 endpoints (IOCs provided).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.