SHub Stealer Variant Malware Targets Major Browsers and Crypto Wallets
Key Takeaways A new, advanced variant of the SHub Stealer, dubbed “Reaper,” is actively targeting macOS users. The malware leverages sophisticated social engineering and automation to...
Key Takeaways
- A new, advanced variant of the SHub Stealer, dubbed “Reaper,” is actively targeting macOS users.
- The malware leverages sophisticated social engineering and automation to steal credentials from major web browsers and funds from popular cryptocurrency wallets.
- Reaper establishes persistence on compromised Macs by masquerading as a legitimate Google update service.
- Security researchers at Moonlock identified this campaign, highlighting a growing trend of “ClickFix” automation among macOS threat actors.
Sophisticated SHub Reaper Malware Strikes macOS Users
A more advanced and stealthy variant of the SHub Stealer malware, now identified as “Reaper,” poses a significant threat to Mac users, employing sophisticated techniques to evade detection and steal sensitive data. This iteration represents a notable evolution from its predecessors.
Table Of Content
Reaper’s Deceptive Infiltration Tactics
The Reaper build primarily propagates through deceptive websites that mimic legitimate software platforms, ensnaring unsuspecting users. Unlike previous versions that required users to manually execute malicious scripts in their Terminal, Reaper automates the entire infection process. It achieves this by using a fake webpage to silently open the Mac’s Script Editor, pre-loaded with malicious code. A single click from the user is then sufficient to unwittingly initiate the infection.
Researchers at Moonlock documented this new SHub Reaper campaign, noting that this “ClickFix” automation technique has been observed in at least three separate macOS malware campaigns within the last two months. Moonlock’s report, shared with Cyber Security News (CSN), indicates that this method is gaining traction among macOS threat actors who frequently adopt successful tactics from one another.
The attackers behind Reaper go to considerable lengths to appear trustworthy. They create convincing spoofed domains that closely resemble those of well-known brands. Malware payloads are frequently disguised as official Apple security updates, and attackers exploit fake Google Software Update pathways to install persistent backdoors deep within compromised Mac systems. This high level of deception allows SHub Reaper to blend seamlessly with trusted software, lowering user vigilance and facilitating a multi-stage attack that culminates in data theft, crypto wallet depletion, and a covert, attacker-controlled backdoor.
SHub Stealer Expands Its Targets to Browsers and Crypto Wallets
The Reaper build significantly enhances the capabilities of earlier SHub Stealer versions. While previous iterations could already exfiltrate browser data, macOS Keychains, iCloud account information, and Telegram session data, the new variant broadens its scope considerably. It now targets a wide array of popular web browsers, including Chrome, Firefox, Brave, Edge, Opera, Vivaldi, Arc, and Orion, along with their associated extensions.
A critical advancement in Reaper is its method for compromising cryptocurrency. Instead of merely installing fraudulent wallet applications, Reaper directly modifies the code of legitimate desktop wallet applications already present on the Mac to surreptitiously steal funds. Among the targeted wallets are Exodus, Atomic, Ledger Live, Electrum, and Trezor Suite. Furthermore, the malware incorporates an AMOS-style Filegrabber module designed to scan Desktop and Documents folders for valuable files, specifically seeking out formats such as .docx, .wallet, .key, .csv, .xls, and .json.
Upon successful data collection, Reaper bundles the stolen information and transmits it to an attacker-controlled server using the legitimate macOS `curl` command. Before its final exit, the malware installs a disguised backdoor, registering itself as a fake Google update service to ensure persistence across system reboots and maintain stealth.
What You Should Do
- Exercise Extreme Caution: Be highly suspicious of any website that automatically opens your Mac’s Script Editor or Terminal and prompts you to click a “Play” or “Run” button. Legitimate software installations do not typically behave this way. Close such windows immediately.
- Verify Software Sources: Only download software from official vendor websites or the Apple App Store. Avoid third-party download sites or links from unsolicited emails or pop-ups.
- Be Wary of Password Prompts: Never enter your macOS system password into a pop-up that appears immediately after installing software, especially if the prompt seems unexpected or out of context.
- Secure Cryptocurrency: For significant cryptocurrency holdings, consider moving funds to a hardware wallet (cold storage) or a dedicated, air-gapped device separate from your primary Mac.
- Keep Systems Updated: Ensure your macOS operating system and all installed security software (antivirus, EDR) are kept up-to-date with the latest patches and definitions to enhance your system’s defenses against emerging threats.
- Enable Firewall: Configure your macOS firewall to block unauthorized incoming connections.
Indicators of Compromise (IoCs):
| Type | Indicator | Description |
|---|---|---|
| Domain | mlcrosoft[.]co[.]com | Typo-squatted Microsoft domain used to host malware payloads |
| URL | support.apple[.]com/downloads/xprotect-remediator-150.dmg | Fake Apple security update download link used to distribute malware |
| URL | hebsbsbzjsjshduxbs[.]xyz/gate/chunk | Attacker-controlled C2 server endpoint used to exfiltrate stolen data |
| File Path | ~/Library/Application Support/Google/GoogleUpdate.app/Contents/MacOS/ | Directory created by Reaper to hide its backdoor as a fake Google update |
| File Name | GoogleUpdate | Encoded Base64 bash script planted as part of the persistence backdoor |
| LaunchAgent | com.google.keystone.agent.plist | LaunchAgent property list used to register and persist the backdoor |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.