logo

macOS Malware Abuses Fake Google Update for Persistence

ID: 2b7e59e2-8ba8-5845-ab6e-d168a535787a

STIX ID: report--2b7e59e2-8ba8-5845-ab6e-d168a535787a

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Mayura Kathir

...
...

A newly observed SHub macOS infostealer variant named “Reaper” uses typo-squatted lures and the applescript:// scheme to load malicious AppleScript in Script Editor, exfiltrate credentials and files (including wallets), and achieve persistence by impersonating GoogleUpdate via a LaunchAgent. The report details fingerprinting and anti-analysis checks, fileless execution via base64-decoded curl|zsh commands, wallet tampering (trojanized app.asar), C2 endpoints and domains, filesystem indicators, and recommended behavioral detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.