Fake CleanMyMac Site Spreads SHub Stealer, Targets Crypto Wallets
ID: a6148750-a6ee-55fe-9051-ad0fd6446224
STIX ID: report--a6148750-a6ee-55fe-9051-ad0fd6446224
Feed Name: GBHackers
Researchers report a SHub macOS infostealer campaign that uses a fake CleanMyMac download page and a ClickFix-style Terminal command to install a loader which fingerprints victims, fetches an AppleScript prompt to steal login passwords, harvests browser credentials and a wide range of crypto wallet data, implants app-level backdoors in Electron-based wallets to capture seed phrases, and maintains persistence via a LaunchAgent while exfiltrating data to attacker-controlled C2 domains (e.g., res2erch-sl0ut.com).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
