New Reaper Malware Uses Fake Microsoft Domain to Steal macOS Passwords
ID: a28f1d6c-6221-5940-8462-a91b96b850a5
STIX ID: report--a28f1d6c-6221-5940-8462-a91b96b850a5
Feed Name: HackRead
Threat Score
SentinelOne researchers uncovered a macOS infostealer named Reaper (a SHub variant) distributed via typo-squatted download pages for legitimate apps; the malware tricks victims into executing AppleScript that prompts for credentials, exfiltrates browser data, password managers, crypto wallets and documents (splitting large files), installs a persistent backdoor that contacts a C2 server (hebsbsbzjsjshduxbs.xyz) every 60 seconds, and can execute remote commands with elevated privileges.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
