New macOS infostealer impersonates Apple, Microsoft, and Google in a single attack chain
ID: 076c9607-4ba4-5dbe-857f-12437ce4bde4
STIX ID: report--076c9607-4ba4-5dbe-857f-12437ce4bde4
Feed Name: Help Net Security
SentinelOne researchers describe Reaper, a SHub macOS infostealer variant that impersonates Apple, Microsoft, and Google to deliver malicious AppleScript via the applescript:// URL scheme and typo-squatted fake installer pages. The malware fingerprints victims, exfiltrates browser data, Keychain items, developer files, Telegram sessions, and cryptocurrency wallets (attempting to replace wallet app.asar files), uses a Filegrabber to collect user documents, and achieves persistence by installing a LaunchAgent under a GoogleUpdate-like path; the report includes IoCs and detection recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
