SHub Reaper | macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain
ID: e8260fae-48ef-5df9-b63f-53dc386e1e4e
STIX ID: report--e8260fae-48ef-5df9-b63f-53dc386e1e4e
Feed Name: SentinelOne Blog
This report details SentinelOne's analysis of SHub 'Reaper', a macOS infostealer that uses fake WeChat/Miro installers and a typo-squatted domain to deliver AppleScript payloads via the applescript:// scheme; it harvests browsers, keychain, cryptocurrency wallets, and documents, performs chunked uploads to a C2, installs a persistent GoogleUpdate LaunchAgent backdoor, and uses anti-analysis techniques—the report includes network and filesystem IOCs, build identifiers, and recommended detection points.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
