PULSE NAME
Fake CleanMyMac site installs SHub Stealer and backdoors crypto wallets
WHITE AlienVault 2026-03-09 Modified: 2026-03-09
6
IOCs
LOW VOLUME
A deceptive website impersonating CleanMyMac tricks users into installing SHub Stealer, a sophisticated macOS malware. The malware steals sensitive data, including passwords, browser data, cryptocurrency wallets, and Telegram sessions. It can also modify wallet apps to steal recovery phrases. The attack begins with users pasting a command into Terminal, which downloads and executes a malicious script. The malware performs extensive data collection from various browsers and wallet applications, and installs persistent backdoors in certain crypto wallet apps. SHub Stealer is part of a growing family of AppleScript-based macOS infostealers, demonstrating increasing sophistication in targeting Mac users.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
SHub Stealer MacSync Stealer Odyssey Stealer Atomic Stealer
Indicators of Compromise (6)
All URL domain
TYPEINDICATORDESCRIPTIONCREATED
URL http://res2erch-sl0ut.com/debug/payload.applescript 2026-03-09
URL http://res2erch-sl0ut.com/gate 2026-03-09
URL http://wallets-gate.io/api/injection 2026-03-09
domain cleanmymacos.org 2026-03-09
domain res2erch-sl0ut.com 2026-03-09
domain wallets-gate.io 2026-03-09