logo

Bypassing Terminal Protections: New SHub “Reaper” Variant Abuses AppleScript to Loot macOS Endpoints

ID: 49d7ba07-eeb8-50ad-8cd1-46377446832b

STIX ID: report--49d7ba07-eeb8-50ad-8cd1-46377446832b

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Ddos

...
...

SentinelOne uncovered a new Reaper build of the SHub Stealer family targeting macOS that uses signed fake installers (e.g., WeChat, Miro) and a multi-stage delivery pipeline to evade macOS protections. Reaper hosts payloads on typo-squatted domains, runs under the guise of Apple/Google update components, drops a persistent LaunchAgent named to mimic GoogleUpdate, and harvests system profiles, browser credentials, cookies, crypto wallets and high-value documents before exfiltrating data in chunked uploads to a remote C2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.