New infostealer malware hides on Mac in disguise


HTML source code showing the construction of the malicious AppleScript. Image credit: SentinelOne

Security researchers say a new macOS infostealer called SHub Reaper disguises itself as Apple security software to steal passwords, cryptocurrency wallets, and sensitive files.

The malware abuses AppleScript and legitimate macOS system processes to hide its activity and avoid some traditional malware scanning tools.

SentinelOne said Reaper is a more advanced version of the SHub Stealer malware family that has circulated through macOS-focused criminal campaigns for the last two years. Earlier SHub variants relied on fake installers and “ClickFix” social engineering tricks that pushed victims into pasting malicious commands into Terminal.

Reaper expands on those tactics by abusing trusted macOS tools and familiar branding to make the malware look legitimate. Attackers now move that process into Script Editor through the `applescript://` URL scheme.

The shift helps bypass some of the protections Apple added in macOS Tahoe 26.4 for Terminal-based attack chains. Different stages of the infection chain use different disguises to make the malware look legitimate.

Victims may download fake WeChat or Miro installers from domains designed to resemble Microsoft infrastructure. Later stages present fake Apple security updates and hide persistence files inside directories that mimic Google Software Update components.

The attack starts with malicious websites that fingerprint visitors before delivering malware payloads. Web pages collect system information, WebGL data, VPN indicators, browser extensions, and signs of virtual machines or security research tools.

Scripts search for password managers including 1Password, Bitwarden, and LastPass alongside cryptocurrency wallet extensions such as MetaMask and Phantom. Sites also deploy anti-analysis protections that interfere with browser developer tools, intercept shortcuts like F12, and trigger debugger loops that repeatedly pause execution.

Some pages replace their content with a Russian-language “Access Denied” message after detecting analysis attempts.

After a victim clicks “Run” in Script Editor, the malware displays an Apple XProtectRemediator security update while executing hidden commands in the background. Attackers padded the malicious AppleScript with fake installer text and ASCII art to push the dangerous commands below the visible window.

Malicious behavior hides behind what appears to be a routine Apple security process. Later stages ask users for their macOS password and capture those credentials during execution. Victims then see a fake compatibility error designed to reduce suspicion after the theft occurs.

Legitimate macOS system processes play a central role in the attack chain instead of obvious malicious apps. Attackers prefer AppleScript and shell-script execution because they blend into normal system activity and bypass traditional file-scanning protections like Apple’s XProtect framework.

Reaper expands beyond credential theft into persistent macOS compromise

Credential and cryptocurrency wallet theft remain central parts of the malware’s behavior. Targets include Chrome, Firefox, Brave, Edge, Opera, Vivaldi, Arc, and Orion alongside wallet applications including Exodus, Atomic Wallet, Ledger Live, Electrum, and Trezor Suite.

Additional theft targets include macOS Keychain data, Telegram session information, browser extensions, and developer-related files.

The newer build adds an AMOS-style document theft routine. Desktop and Documents folders are searched for business and financial files including Word documents, spreadsheets, JSON files, wallet files, and remote desktop configurations.

Files above specific size thresholds are skipped, including PNG images larger than 6 MB. Total collection is capped at 150 MB before the malware compresses and uploads stolen data in chunks to its command-and-control infrastructure.

After collecting data, the malware attempts to compromise cryptocurrency wallet applications directly. Active wallet processes are terminated before internal application resources are replaced with attacker-controlled `app.asar` files.

Two dark macOS System Preferences dialogs: top shows padlock, password field, Continue button; bottom shows red stop sign warning that the Mac does not support the application, with OK button.

Later stages ask users for their macOS password and capture those credentials during execution. Image credit: SentinelOne

Quarantine attributes are removed afterward, and ad hoc code signing helps modified applications continue running on macOS systems.

Persistence is one of the biggest changes in the Reaper build. The malware installs a LaunchAgent disguised as Google software infrastructure inside the user’s Library folder.

Attackers create a fake `GoogleUpdate.app` structure and register a `com.google.keystone.agent.plist` LaunchAgent that executes every 60 seconds. The fake LaunchAgent closely resembles Google’s legitimate Keystone update service, making the persistence mechanism harder to notice during casual inspection.

Remote servers then deliver additional commands, execute returned payloads with the current user’s privileges, and delete temporary files afterward.

Persistence pushes the malware beyond simple credential theft. Earlier macOS infostealers often collected data and disappeared, but Reaper maintains a foothold that can support future payloads or remote access.

Native tools, fake update prompts, and trusted Apple, Microsoft, and Google branding now play a larger role in macOS malware campaigns. Reaper rotates between those brands to make malicious activity appear routine to many users.

How Mac users can stay safe

Users can reduce exposure to this campaign by avoiding scripts or installers from untrusted websites, especially pages claiming a manual security update is required. Apple doesn’t usually ask users to open Script Editor and click “Run” to install updates.

SentinelOne said the campaign used typo-squatted domains designed to resemble Microsoft infrastructure. Checking URLs carefully before downloading software can help users avoid spoofed installer sites.

Mac users should download software from official developer sites or the Mac App Store instead of installer pages shared through ads, social posts, or unsolicited messages. Unexpected password prompts during installation, especially alongside vague error messages or claims that an update failed, should raise suspicion.

Advanced users and administrators can monitor for unusual AppleScript or `osascript` activity, unexpected LaunchAgents, and network traffic tied to Script Editor. SentinelOne also recommended watching for suspicious AppleScript execution and fake trusted-vendor directories and LaunchAgents used for persistence.



Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


Netflix is home to a large library of exclusive content: from Netflix Original shows and movies to documentaries, this catalog is available to stream only on this platform. You can find many genres, tropes, and styles within this exclusive library, but how good are the titles?

Platforms like IMDb and Rotten Tomatoes allow you to find the most highly-rated and/or popular shows and movies, and these reviews can also help you shape your watch list. Here are five highly-rated Netflix Original films to watch in April.

The films on this list have been picked based on their IMDb rating, with all films having a rating higher than 7.5 out of 10. All of them are also Netflix Original films.

The Mitchells vs. the Machines

A roadtrip, an apocalypse, and a family with a mission

If you’re an animation fan, you might have come across works by Sony Pictures Animation, which is the studio behind Netflix’s Oscar-winning film KPop Demon Hunters. One of its best films that you don’t want to miss is The Mitchells vs. The Machines, a sci-fi family comedy following the dysfunctional Mitchells. As an impending robot apocalypse builds, the Mitchell parents, Rick and Linda, set out to drop their daughter Katie at her film school after Katie and Rick fight.

Their family road trip turns into a nightmare when the world’s electronics gain consciousness and rise to rebel against humans, setting off a chain of events that could end the age of humans. The Mitchells vs. The Machines is one of Netflix’s most-viewed animated works to date, being watched by over 53 million households within 28 days of its release. The movie is emotional yet humorous, with a quirky and fun animation style that keeps you glued to the screen.

The Trial of the Chicago 7

A courtroom drama based on real events

The Trial of the Chicago 7 is a perfect combination of courtroom drama meets political thriller. Based on real events, it follows the infamous 1969 trial of seven defendants charged by the federal government with conspiracy and crossing state lines with the intention of inciting riots during the Democratic National Convention in Chicago. As they are set up against a biased legal system and a judge that can make or break their cases, the defendants face an unfamiliar battleground.

The film features performances from a star-studded ensemble cast, including actors like Eddie Redmayne, Yahya Abdul-Mateen II, Sacha Baron Cohen, Daniel Flaherty, Joseph Gordon-Levitt, Michael Keaton, Frank Langella, and John Carroll Lynch.

Beasts of No Nation

A brutal film that holds the mirror to the reality of war

If you like to stream war movies, Beasts of No Nation is a critically acclaimed film you should add to your watch list. This is one of those films that fall under the category of “films you should watch once and never again” for many viewers. Set in a small, war-torn West African village, the tragic and brutal war drama explores the journey of Agu, a young boy who escapes a village-wide execution in a civil war.

Taken under the wing of a ruthless Commandment (Idris Elba), Agu is quickly exposed to his new reality, transforming from an innocent boy to a war-hardened soldier and killer on the run. As the war worsens, Agu and his army’s lives hang in the balance, with Agu’s state of mind declining due to the brutality of his actions.

Elba’s strong performance in the film earned him several accolades, including a SAG Award.

The Irishman

Don’t skip this if you’re a fan of gangster films

When it comes to epic gangster films, you can’t go wrong with a quintessential one like Martin Scorsese’s The Irishman. This slow-burning crime drama, which is set across multiple decades, from the 1950s onwards, tells the real story of Frank Sheeran, a World War II veteran turned hitman who becomes deeply involved with the Bufalino crime family. As he rises up the ranks, Sheeran forms a close bond with powerful Teamster Jimmy Hoffa. As the story unfolds, Sheeran’s choices and the complex web of organized crime are explored.

The Irishman features an all-star cast, including Robert De Niro, Al Pacino, Joe Pesci, Harvey Keitel, and more. It marks the ninth collaboration between De Niro and Scorsese.

Klaus

May the spirit of Christmas be with you

Even if winter has melted away, a must-watch Christmas film is the animated movie Klaus. This highly rated Netflix film is an alternative origin story of Santa Claus. The animation in this film is incredible, adding to a story that is a perfect holiday-time family watch.

The movie focuses on Jesper, a lazy and privileged postman who is sent by his Royal Postmaster General father to the remote island town of Smeerensburg. Here, he must establish a post office and post 6,000 letters within a year. Desperate to meet this quota and avoid being cut from the family fortune, Jesper teams up with a reclusive toy maker named Klaus. As their unlikely partnership grows, the town is transformed, with children getting delightful toys in exchange for letters. Christmas brings about a demand for more toys, while the town throws obstacles in the way.

The film was nominated for the 92nd Academy Awards in the Best Animated Feature category, making it the first animated film from Netflix to be nominated for an Academy Award.


You can find more Netflix Original content by going through the exclusive library or searching for Only on Netflix or Netflix Original. To filter your titles by genres and tropes, make use of Netflix’s secret codes for easy browsing.

Subscription with ads

Yes, $8/month

Simultaneous streams

Two or four

Stream licensed and original programming with a monthly Netflix subscription.




Source link