PULSE NAME
macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain
WHITE AlienVault 2026-05-18 Modified: 2026-05-18
9
IOCs
LOW VOLUME
A new variant of SHub Stealer dubbed 'Reaper' targets macOS users through fake WeChat and Miro installers, employing sophisticated multi-stage delivery chains that spoof Apple, Google, and Microsoft services. The malware leverages the applescript:// URL scheme to bypass Terminal-based defenses, conducting extensive fingerprinting and anti-analysis checks before execution. Reaper harvests browser credentials, cryptocurrency wallets, developer configurations, iCloud data, and Telegram sessions. It includes an AMOS-style document theft module targeting files under 150MB with chunked uploads. The variant establishes persistence through a fake Google Software Update LaunchAgent and installs a backdoor for remote code execution. The infection specifically avoids CIS regions and employs extensive anti-analysis techniques including WebGL fingerprinting, VM detection, and DevTools interference.
Indicators of Compromise (9)
All FileHash-MD5 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 c917fcf8314228862571f80c9e4a871e 2026-05-18
URL http://hebsbsbzjsjshduxbs.xyz/api/bot/heartbeat 2026-05-18
URL http://hebsbsbzjsjshduxbs.xyz/api/debug/event 2026-05-18
URL http://hebsbsbzjsjshduxbs.xyz/gate 2026-05-18
URL http://hebsbsbzjsjshduxbs.xyz/gate/chunk 2026-05-18
domain hebsbsbzjsjshduxbs.xyz 2026-05-18
domain mlroweb.com 2026-05-18
domain qq-0732gwh22.com 2026-05-18
URL http://mlcrosoft.co.com 2026-05-18