New SHub Stealer Malware Expands Attacks on Browsers and Wallets

Threat actors are leveraging fake software websites to distribute Reaper, a significantly updated version of the macOS SHub Stealer.

By impersonating popular applications like WeChat and Miro, cybercriminals are successfully deploying this malware to unsuspecting Mac users.

The campaign utilizes a streamlined variation of the ClickFix technique that automates malicious code execution, making the attack much harder to spot.

SHub Stealer Targets Wallets

Traditional ClickFix attacks rely on social engineering to trick victims into manually copying and pasting malicious scripts into the macOS Terminal.

This new campaign takes a dangerous shortcut by directly launching the native Script Editor app, which is preloaded with malicious code.

When users click the native “Play” button in the Script Editor, the infection chain begins automatically.

The Fake WeChat code shared by SentinelOne opens up on your Script Editor. Hidden below, and out of sight, is the malicious code that triggers the infection chain. Image: Screenshot, Moonlock (Source: moonlock)
The Fake WeChat code shared by SentinelOne opens up on your Script Editor. Hidden below, and out of sight, is the malicious code that triggers the infection chain. Image: Screenshot, Moonlock (Source: moonlock)

This marks the third time in two months that security researchers have observed threat actors bypassing manual Terminal interactions in favor of this automated, highly effective approach.

To build credibility, attackers heavily spoof major tech brands to disguise their infrastructure. They host their payloads on typo-squatted domains like mlcrosoft[.]co[.]com and disguise them as legitimate Apple security updates.

In this image, the Apple Developers’ Mac Automation Scripting Guide shows the basics of the tool. If this app opens up with code on it on your Mac, do not click the Play button without being 100% sure you know what you are doing. Image: Screenshot, Moonlock (Source: moonlock)
In this image, the Apple Developers’ Mac Automation Scripting Guide shows the basics of the tool. If this app opens up with code on it on your Mac, do not click the Play button without being 100% sure you know what you are doing. Image: Screenshot, Moonlock (Source: moonlock)

The malware even establishes persistence by hiding a backdoor within a fake Google Software Update directory.

Threat actors actively exploit the technical complexity of native macOS tools, banking on the fact that most users trust default applications like the Script Editor.

Once the initial payload executes, Reaper immediately checks the system’s keyboard configuration. If the Mac uses a Russian layout, the malware automatically halts execution to avoid targeting regional systems.

For some reason, the official Apple Script Editor developer’s guide mistakenly identifies the Record icon with the Play icon. Raising awareness on what the Script Editor Play button does is fundamental in preventing this new type of ClickFix attack. Image: Screenshot, Moonlock (Source: moonlock)
For some reason, the official Apple Script Editor developer’s guide mistakenly identifies the Record icon with the Play icon. Raising awareness on what the Script Editor Play button does is fundamental in preventing this new type of ClickFix attack. Image: Screenshot, Moonlock (Source: moonlock)

For all other users, Reaper triggers a fake system password prompt to escalate privileges and access restricted local resources.

Rather than simply swapping out crypto wallets with fake versions, Reaper modifies the core code of your legitimate desktop wallet applications to siphon funds.

After compiling the stolen data, the malware compresses it. It uses the native macOS curl command to exfiltrate the payload to an attacker-controlled command-and-control server.

Finally, Reaper ensures it maintains access to the compromised machine.

It drops an encoded bash script and registers it as a LaunchAgent property list to run silently in the background. Protecting your system from these advanced stealers requires a layered defense strategy.

Using dedicated macOS security tools, such as Moonlock, can help detect hidden threats in real time, including malicious Terminal scripts.

Keep your crypto assets in offline cold wallets when possible, and remember that legitimate software installations will never randomly prompt for your system password after initial setup.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories