logo

SHub Reaper | macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain

ID: e8260fae-48ef-5df9-b63f-53dc386e1e4e

STIX ID: report--e8260fae-48ef-5df9-b63f-53dc386e1e4e

Feed Name: SentinelOne Blog

Threat Score
75/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: Phil Stokes

...
...

This report details SentinelOne's analysis of SHub 'Reaper', a macOS infostealer that uses fake WeChat/Miro installers and a typo-squatted domain to deliver AppleScript payloads via the applescript:// scheme; it harvests browsers, keychain, cryptocurrency wallets, and documents, performs chunked uploads to a C2, installs a persistent GoogleUpdate LaunchAgent backdoor, and uses anti-analysis techniques—the report includes network and filesystem IOCs, build identifiers, and recommended detection points.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.