HeadlinesBriefing favicon HeadlinesBriefing.com

SHub Reaper Malware Targets Macs

AppleInsider •
×

Security researchers have uncovered a new macOS infostealer called SHub Reaper that disguises itself as official Apple security tools to steal passwords, cryptocurrency wallets, and sensitive files. This advanced malware represents a more sophisticated evolution of the SHub Stealer family that has targeted macOS systems for the past two years.

Reaper abuses AppleScript and legitimate macOS processes to hide its activity and bypass traditional security scanning. Unlike earlier variants that relied on social engineering tricks, this malware uses the `applescript://` URL scheme in Script Editor and fake Apple XProtectRementicator security prompts to appear legitimate while stealing data in the background.

Victims encounter fake security updates and typo-squatted domains resembling Microsoft infrastructure. The malware maintains persistence through a fake Google LaunchAgent and can compromise cryptocurrency wallets directly. Users should avoid scripts from untrusted sources and download software only from official developers or the Mac App Store to reduce exposure.