Do fear the Reaper - stealer swipes macOS users' passwords, wallets, then backdoors them
ID: c07b9f3d-fe0b-5e37-a938-c3c285f0d479
STIX ID: report--c07b9f3d-fe0b-5e37-a938-c3c285f0d479
Feed Name: The Register (Security)
Threat Score
# Executive summary Reaper is an updated SHub macOS infostealer that lures users to typo-squatted installer pages, leverages Apple Script Editor to run malicious AppleScript (bypassing Terminal protections), harvests credentials, browser data, iCloud/Keychain items and multiple cryptocurrency wallets, and installs a GoogleUpdate-like LaunchAgent backdoor that beacons to a C2 and can execute remote payloads, enabling ongoing theft and lateral actions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
