Fake CleanMyMac site installs SHub Stealer and backdoors crypto wallets
ID: 83d64acd-1a5f-5161-a68b-85cb8a6509b6
STIX ID: report--83d64acd-1a5f-5161-a68b-85cb8a6509b6
Feed Name: Malwarebytes Blog
SHub Stealer is a sophisticated macOS infostealer distributed via a fake CleanMyMac site that lures users into pasting a Terminal command (ClickFix). Once executed it harvests macOS Keychain, browser credentials, Telegram sessions, developer tokens, and numerous cryptocurrency wallets; it can also replace Electron wallet app code to exfiltrate seed phrases, maintain persistence via a LaunchAgent, and accept remote commands from C2 servers (notable domains: cleanmymacos.org, res2erch-sl0ut.com, wallets-gate.io).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
