logo

Fake CleanMyMac site installs SHub Stealer and backdoors crypto wallets

ID: 83d64acd-1a5f-5161-a68b-85cb8a6509b6

STIX ID: report--83d64acd-1a5f-5161-a68b-85cb8a6509b6

Feed Name: Malwarebytes Blog

Threat Score
80/100

Date Published: 2026-03-06

Date Updated: 2026-04-28

...
...

SHub Stealer is a sophisticated macOS infostealer distributed via a fake CleanMyMac site that lures users into pasting a Terminal command (ClickFix). Once executed it harvests macOS Keychain, browser credentials, Telegram sessions, developer tokens, and numerous cryptocurrency wallets; it can also replace Electron wallet app code to exfiltrate seed phrases, maintain persistence via a LaunchAgent, and accept remote commands from C2 servers (notable domains: cleanmymacos.org, res2erch-sl0ut.com, wallets-gate.io).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.