logo

New Reaper Malware Uses Fake Microsoft Domain to Steal macOS Passwords

ID: a28f1d6c-6221-5940-8462-a91b96b850a5

STIX ID: report--a28f1d6c-6221-5940-8462-a91b96b850a5

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: Deeba Ahmed

...
...

SentinelOne researchers uncovered a macOS infostealer named Reaper (a SHub variant) distributed via typo-squatted download pages for legitimate apps; the malware tricks victims into executing AppleScript that prompts for credentials, exfiltrates browser data, password managers, crypto wallets and documents (splitting large files), installs a persistent backdoor that contacts a C2 server (hebsbsbzjsjshduxbs.xyz) every 60 seconds, and can execute remote commands with elevated privileges.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.