logo

New macOS infostealer impersonates Apple, Microsoft, and Google in a single attack chain

ID: 076c9607-4ba4-5dbe-857f-12437ce4bde4

STIX ID: report--076c9607-4ba4-5dbe-857f-12437ce4bde4

Feed Name: Help Net Security

Threat Score
72/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Sinisa Markovic

...
...

SentinelOne researchers describe Reaper, a SHub macOS infostealer variant that impersonates Apple, Microsoft, and Google to deliver malicious AppleScript via the applescript:// URL scheme and typo-squatted fake installer pages. The malware fingerprints victims, exfiltrates browser data, Keychain items, developer files, Telegram sessions, and cryptocurrency wallets (attempting to replace wallet app.asar files), uses a Filegrabber to collect user documents, and achieves persistence by installing a LaunchAgent under a GoogleUpdate-like path; the report includes IoCs and detection recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.