Bypassing Terminal Protections: New SHub “Reaper” Variant Abuses AppleScript to Loot macOS Endpoints
ID: 49d7ba07-eeb8-50ad-8cd1-46377446832b
STIX ID: report--49d7ba07-eeb8-50ad-8cd1-46377446832b
Feed Name: securityonline.info
SentinelOne uncovered a new Reaper build of the SHub Stealer family targeting macOS that uses signed fake installers (e.g., WeChat, Miro) and a multi-stage delivery pipeline to evade macOS protections. Reaper hosts payloads on typo-squatted domains, runs under the guise of Apple/Google update components, drops a persistent LaunchAgent named to mimic GoogleUpdate, and harvests system profiles, browser credentials, cookies, crypto wallets and high-value documents before exfiltrating data in chunked uploads to a remote C2.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
