logo

Do fear the Reaper - stealer swipes macOS users' passwords, wallets, then backdoors them

ID: c07b9f3d-fe0b-5e37-a938-c3c285f0d479

STIX ID: report--c07b9f3d-fe0b-5e37-a938-c3c285f0d479

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2026-05-18

Date Updated: 2026-05-19

...
...

# Executive summary Reaper is an updated SHub macOS infostealer that lures users to typo-squatted installer pages, leverages Apple Script Editor to run malicious AppleScript (bypassing Terminal protections), harvests credentials, browser data, iCloud/Keychain items and multiple cryptocurrency wallets, and installs a GoogleUpdate-like LaunchAgent backdoor that beacons to a C2 and can execute remote payloads, enabling ongoing theft and lateral actions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.