macOS Malware Abuses Fake Google Update for Persistence
ID: 2b7e59e2-8ba8-5845-ab6e-d168a535787a
STIX ID: report--2b7e59e2-8ba8-5845-ab6e-d168a535787a
Feed Name: GBHackers
A newly observed SHub macOS infostealer variant named “Reaper” uses typo-squatted lures and the applescript:// scheme to load malicious AppleScript in Script Editor, exfiltrate credentials and files (including wallets), and achieve persistence by impersonating GoogleUpdate via a LaunchAgent. The report details fingerprinting and anti-analysis checks, fileless execution via base64-decoded curl|zsh commands, wallet tampering (trojanized app.asar), C2 endpoints and domains, filesystem indicators, and recommended behavioral detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
