PULSE NAME
Fake CleanMyMac Site Spreads SHub Stealer Targeting Crypto Wallets
WHITE cryptocti 2026-03-10 Modified: 2026-03-10
3
IOCs
LOW VOLUME
Threat actors were observed targeting cryptocurrency wallets through a fake CleanMyMac website distributing SHub Stealer malware. The campaign uses a phishing technique that prompts users to paste a command into the Terminal, which initiates the malware. Once executed, the malware steals browser data such as saved passwords, cookies and autofill information also targets cryptocurrency wallet data.
Indicators of Compromise (3)
All domain
TYPEINDICATORDESCRIPTIONCREATED
domain cleanmymacos.org 2026-03-10
domain res2erch-sl0ut.com 2026-03-10
domain wallets-gate.io 2026-03-10