SHub macOS infostealer variant spoofs Apple security updates
ID: c388a18b-cf78-52e4-9e0a-8dc368f8e5fe
STIX ID: report--c388a18b-cf78-52e4-9e0a-8dc368f8e5fe
Feed Name: Bleeping Computer
Reaper, a new variant of the SHub macOS infostealer, leverages the applescript:// URL scheme to open a preloaded malicious AppleScript that presents a fake Apple security update, downloads and executes a shell payload, then harvests browser credentials, crypto wallet extensions and desktop wallets, Keychain items, iCloud and Telegram data, and targeted files; it evades recent Terminal paste mitigations, clears quarantine attributes, uses ad-hoc code signing to avoid Gatekeeper, installs a LaunchAgent for persistence and beacons telemetry to a Telegram bot, while SentinelOne published IOCs and detection/mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
