logo

SHub macOS infostealer variant spoofs Apple security updates

ID: c388a18b-cf78-52e4-9e0a-8dc368f8e5fe

STIX ID: report--c388a18b-cf78-52e4-9e0a-8dc368f8e5fe

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: Bill Toulas

...
...

Reaper, a new variant of the SHub macOS infostealer, leverages the applescript:// URL scheme to open a preloaded malicious AppleScript that presents a fake Apple security update, downloads and executes a shell payload, then harvests browser credentials, crypto wallet extensions and desktop wallets, Keychain items, iCloud and Telegram data, and targeted files; it evades recent Terminal paste mitigations, clears quarantine attributes, uses ad-hoc code signing to avoid Gatekeeper, installs a LaunchAgent for persistence and beacons telemetry to a Telegram bot, while SentinelOne published IOCs and detection/mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.