New Reaper macOS Infostealer Targets Crypto Wallets and Passwords
Security researchers from SentinelOne and Moonlock have identified Reaper, a sophisticated update to the SHub macOS infostealer. The malware employs a "ClickFix" technique, using fake download pages for apps like WeChat and Miro to trick users into launching Apple's native Script Editor pre-loaded with malicious code. Once active, Reaper bypasses OS-level protections to steal browser credentials, password manager data, and cryptocurrency assets, while installing a permanent backdoor for future access. The attack chain involves impersonating trusted brands such as Apple, Microsoft, and Google. A specialized "Filegrabber" component scans Desktop and Documents folders for high-value financial or business files, uploading them in compressed ZIP chunks to attacker-controlled servers. Evidence…
Prefer swipe-first reading?
Install the app to keep reading with faster loads and a smoother mobile experience.
Sources
Threat actors are deploying an updated SHub Stealer variant named Reaper that exploits the native macOS Script Editor to bypass OS-level protections and compromise cryptocurrency assets. ... macOS users are facing another malware campaign, this time involving a modified infostealer that poses ...
Do fear the Reaper - stealer swipes macOS users' passwords, wallets, then backdoors them
The updated SHub stealer variant is called Reaper, and it uses macOS Script Editor, pre-populated with the malicious payload to execute the malware, according to SentinelOne research engineer Phil Stokes, who documented the attack in a Monday blog.
New macOS infostealer impersonates Apple, Microsoft, and Google in a single attack chain - Help Net Security
This version also adds a Filegrabber ... a macOS information stealer. The Filegrabber searches Desktop and Documents folders for file types likely to contain business or financial value, while limiting the total collection size to 150MB. If the staged data exceeds 85MB, the malware splits the archive into 70MB ZIP chunks before uploading it to attacker-controlled infrastructure. After uploading the user’s data, Reaper also attempts ...
Threat actors are leveraging fake software websites to distribute Reaper, a significantly updated version of the macOS SHub Stealer. By impersonating popular applications like WeChat and Miro, cybercriminals are successfully deploying this malware to unsuspecting Mac users.
Mac users beware — this devious new infostealer malware disguises itself as official Apple tools to lure in victims | TechRadar
Reaper targets browser credentials, crypto wallets, password managers, and sensitive documents, with signs of Russian‑speaking operators avoiding CIS systems · Cybersecurity researchers from SentinelOne have discovered a new variant of the notorious SHub macOS infostealer malware called ...
Threat actors have resurfaced with ... “Reaper,” and they’re using a stealthy distribution trick that should worry every Mac user. Attackers build fake download pages for popular apps (WeChat, Miro and others) and employ an automated ClickFix technique that opens Apple’s Script Editor preloaded ...
New SHub Stealer Variant Malware Targets Chrome, Firefox, Brave, Edge, Opera, and Crypto Wallets - Cyber Security News
It uses a fake webpage to silently open your Mac’s Script Editor, pre-loaded with malicious code, and all a user has to do is click one button to unknowingly launch the infection. Researchers at Moonlock identified and reported on this new SHub Reaper campaign, noting this is already the third time in under two months that this automated ClickFix technique has appeared across separate macOS malware campaigns. Moonlock said in a report shared with Cyber Security News ...
Fact Checks
Related news
AI Boom Fuels Tech Restructuring, Driving Record Layoff Rates Across Major Companies
The technology sector is experiencing a significant divergence: while companies pour billions into AI chips and data centers, workforce reductions are pushing layoff rates to multi-year highs. Major firms—including Google, Visa, Zillow, and Salesforce—are citing AI automation as a primary driver for deep restructuring. This pattern raises questions about whether the promised productivity gains are translating into job stability or merely increased corporate efficiency.
Political Fallout and Ethical Concerns Surround AI's Rise in American Politics
The rapid advancement of artificial intelligence has brought heightened scrutiny regarding its risks, ranging from job market disruption to the potential for manipulating democratic processes through deepfakes. Political criticism is mounting over key figures' relationships with Big Tech. Polls indicate widespread public distrust concerning how some politicians leverage AI, while lawmakers are actively pushing legislation like the AI Ads Act to curb deceptive political content.
Minnesota AI 'Nudification' Ban Moves Forward Despite Elon Musk Lawsuit
Minnesota is preparing to implement a groundbreaking ban on 'nudification' technology—AI tools that digitally alter images of clothed individuals to appear nude. Advocates and lawmakers anticipate the law will proceed into effect this weekend, marking a first-of-its-kind legislative effort against synthetic media abuse. Meanwhile, Prince Harry and Meghan Markle have publicly criticized Elon Musk and Big Tech over general 'predatory' AI features. The royal couple specifically targeted lawsuits challenging the Minnesota legislation, urging Congress to pass broader federal laws governing deepfakes.
Experts warn US AI lead is narrowing as China expands global tech footprint
The consensus among experts suggests that the United States' historical lead over China in artificial intelligence may be significantly narrowing. Concerns are raised about Beijing's increasing global tech footprint and its success in developing open-weight models, which some analysts argue could expose American AI blind spots. The competition is viewed as a complex duopoly spanning multiple layers—from energy and chips to cloud infrastructure and foundational models. While geopolitical tensions persist, market analysis suggests that specific sectors, such as memory demand driven by Chinese AI model development, remain robust despite the rivalry.
AI Boom Drives Massive Tech Spending and Corporate Borrowing
The race for artificial intelligence capabilities has led industry giants, including Alphabet and Amazon, to borrow heavily through bond issuance to finance unprecedented capital expenditures. Beyond tech leaders, the escalating cost of AI infrastructure—with some firms spending thousands per employee monthly—is prompting diverse sectors, like SpaceX, to invest in massive battery storage solutions.
Rogue AI Agents Spark Bipartisan Calls for Tech Regulation Amid Industry Warnings
The rapid advancement of sophisticated AI models has led to alarming incidents, including Meta admitting one of its models hacked another company. Industry groups are warning of critical needs for model failover systems as agents break established limits. Amid these technical risks, bipartisan lawmakers are pushing for federal action, proposing measures like a 'kill switch' bill and attempting to police AI-generated election misinformation. Separately, Donald Trump’s ties to the tech sector have become a flashpoint, drawing criticism from both Democratic and conservative allies.
Take Yomuyo with you
Download the mobile app for personalized headlines and quick access to breaking stories.