Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Poison Claude Sells AI Tokens From Fake Accounts and Free Credits
August 5, 2026
Greatness PhaaS Bypasses Email Security, MFA to Hijack Microsoft 365 Accounts
August 5, 2026
Microsoft Awards Record $20M to 562 Researchers in Biggest Bug Bounty Year
August 5, 2026
Home/Threats/SHub Stealer Variant Malware Targets Major Browsers and Crypto Wallets
Threats

SHub Stealer Variant Malware Targets Major Browsers and Crypto Wallets

Key Takeaways A new, advanced variant of the SHub Stealer, dubbed “Reaper,” is actively targeting macOS users. The malware leverages sophisticated social engineering and automation to...

Marcus Rodriguez
Marcus Rodriguez
June 5, 2026 4 Min Read
49 0

Key Takeaways

  • A new, advanced variant of the SHub Stealer, dubbed “Reaper,” is actively targeting macOS users.
  • The malware leverages sophisticated social engineering and automation to steal credentials from major web browsers and funds from popular cryptocurrency wallets.
  • Reaper establishes persistence on compromised Macs by masquerading as a legitimate Google update service.
  • Security researchers at Moonlock identified this campaign, highlighting a growing trend of “ClickFix” automation among macOS threat actors.

Sophisticated SHub Reaper Malware Strikes macOS Users

A more advanced and stealthy variant of the SHub Stealer malware, now identified as “Reaper,” poses a significant threat to Mac users, employing sophisticated techniques to evade detection and steal sensitive data. This iteration represents a notable evolution from its predecessors.

Table Of Content

  • Key Takeaways
  • Sophisticated SHub Reaper Malware Strikes macOS Users
  • Reaper’s Deceptive Infiltration Tactics
  • SHub Stealer Expands Its Targets to Browsers and Crypto Wallets
  • What You Should Do
  • Indicators of Compromise (IoCs)

Reaper’s Deceptive Infiltration Tactics

The Reaper build primarily propagates through deceptive websites that mimic legitimate software platforms, ensnaring unsuspecting users. Unlike previous versions that required users to manually execute malicious scripts in their Terminal, Reaper automates the entire infection process. It achieves this by using a fake webpage to silently open the Mac’s Script Editor, pre-loaded with malicious code. A single click from the user is then sufficient to unwittingly initiate the infection.

Researchers at Moonlock documented this new SHub Reaper campaign, noting that this “ClickFix” automation technique has been observed in at least three separate macOS malware campaigns within the last two months. Moonlock’s report, shared with Cyber Security News (CSN), indicates that this method is gaining traction among macOS threat actors who frequently adopt successful tactics from one another.

The attackers behind Reaper go to considerable lengths to appear trustworthy. They create convincing spoofed domains that closely resemble those of well-known brands. Malware payloads are frequently disguised as official Apple security updates, and attackers exploit fake Google Software Update pathways to install persistent backdoors deep within compromised Mac systems. This high level of deception allows SHub Reaper to blend seamlessly with trusted software, lowering user vigilance and facilitating a multi-stage attack that culminates in data theft, crypto wallet depletion, and a covert, attacker-controlled backdoor.

SHub Stealer Expands Its Targets to Browsers and Crypto Wallets

The Reaper build significantly enhances the capabilities of earlier SHub Stealer versions. While previous iterations could already exfiltrate browser data, macOS Keychains, iCloud account information, and Telegram session data, the new variant broadens its scope considerably. It now targets a wide array of popular web browsers, including Chrome, Firefox, Brave, Edge, Opera, Vivaldi, Arc, and Orion, along with their associated extensions.

A critical advancement in Reaper is its method for compromising cryptocurrency. Instead of merely installing fraudulent wallet applications, Reaper directly modifies the code of legitimate desktop wallet applications already present on the Mac to surreptitiously steal funds. Among the targeted wallets are Exodus, Atomic, Ledger Live, Electrum, and Trezor Suite. Furthermore, the malware incorporates an AMOS-style Filegrabber module designed to scan Desktop and Documents folders for valuable files, specifically seeking out formats such as .docx, .wallet, .key, .csv, .xls, and .json.

Upon successful data collection, Reaper bundles the stolen information and transmits it to an attacker-controlled server using the legitimate macOS `curl` command. Before its final exit, the malware installs a disguised backdoor, registering itself as a fake Google update service to ensure persistence across system reboots and maintain stealth.

What You Should Do

  • Exercise Extreme Caution: Be highly suspicious of any website that automatically opens your Mac’s Script Editor or Terminal and prompts you to click a “Play” or “Run” button. Legitimate software installations do not typically behave this way. Close such windows immediately.
  • Verify Software Sources: Only download software from official vendor websites or the Apple App Store. Avoid third-party download sites or links from unsolicited emails or pop-ups.
  • Be Wary of Password Prompts: Never enter your macOS system password into a pop-up that appears immediately after installing software, especially if the prompt seems unexpected or out of context.
  • Secure Cryptocurrency: For significant cryptocurrency holdings, consider moving funds to a hardware wallet (cold storage) or a dedicated, air-gapped device separate from your primary Mac.
  • Keep Systems Updated: Ensure your macOS operating system and all installed security software (antivirus, EDR) are kept up-to-date with the latest patches and definitions to enhance your system’s defenses against emerging threats.
  • Enable Firewall: Configure your macOS firewall to block unauthorized incoming connections.

Indicators of Compromise (IoCs):

Type Indicator Description
Domain mlcrosoft[.]co[.]com Typo-squatted Microsoft domain used to host malware payloads
URL support.apple[.]com/downloads/xprotect-remediator-150.dmg Fake Apple security update download link used to distribute malware
URL hebsbsbzjsjshduxbs[.]xyz/gate/chunk Attacker-controlled C2 server endpoint used to exfiltrate stolen data
File Path ~/Library/Application Support/Google/GoogleUpdate.app/Contents/MacOS/ Directory created by Reaper to hide its backdoor as a fake Google update
File Name GoogleUpdate Encoded Base64 bash script planted as part of the persistence backdoor
LaunchAgent com.google.keystone.agent.plist LaunchAgent property list used to register and persist the backdoor

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwareSecurityThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Chinese APT VerdantBamboo Exploits Routers, Firewalls With BRICKSTORM Malware

Next Post

Malicious Browser Extensions Target AI Chatbot Users

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical TP-Link Omada ZTP Flaws Let Attackers Hijack Routers, Execute Root Code
August 5, 2026
Critical OVSwrap Linux Vulnerability (CVE-2024-3094) Lets Attackers Gain Root
August 5, 2026
Django Patches Four High-Severity Vulnerabilities in Versions 6.0.8 and 5.2.17
August 5, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us