logo

Fake CleanMyMac Site Spreads SHub Stealer, Targets Crypto Wallets

ID: a6148750-a6ee-55fe-9051-ad0fd6446224

STIX ID: report--a6148750-a6ee-55fe-9051-ad0fd6446224

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-03-09

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Researchers report a SHub macOS infostealer campaign that uses a fake CleanMyMac download page and a ClickFix-style Terminal command to install a loader which fingerprints victims, fetches an AppleScript prompt to steal login passwords, harvests browser credentials and a wide range of crypto wallet data, implants app-level backdoors in Electron-based wallets to capture seed phrases, and maintains persistence via a LaunchAgent while exfiltrating data to attacker-controlled C2 domains (e.g., res2erch-sl0ut.com).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.