← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain
A new variant of SHub Stealer dubbed 'Reaper' targets macOS users through fake WeChat and Miro installers, employing sophisticated multi-stage delivery chains that spoof Apple, Google, and Microsoft services. The malware leverages the applescript:// URL scheme to bypass Terminal-based defenses, conducting extensive fingerprinting and anti-analysis checks before execution. Reaper harvests browser credentials, cryptocurrency wallets, developer configurations, iCloud data, and Telegram sessions. It includes an AMOS-style document theft module targeting files under 150MB with chunked uploads. The variant establishes persistence through a fake Google Software Update LaunchAgent and installs a backdoor for remote code execution. The infection specifically avoids CIS regions and employs extensive anti-analysis techniques including WebGL fingerprinting, VM detection, and DevTools interference.
MITRE ATT&CK & Malware Families
Indicators of Compromise (9)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | c917fcf8314228862571f80c9e4a871e | — | 2026-05-18 | |
| URL | http://hebsbsbzjsjshduxbs.xyz/api/bot/heartbeat | — | 2026-05-18 | |
| URL | http://hebsbsbzjsjshduxbs.xyz/api/debug/event | — | 2026-05-18 | |
| URL | http://hebsbsbzjsjshduxbs.xyz/gate | — | 2026-05-18 | |
| URL | http://hebsbsbzjsjshduxbs.xyz/gate/chunk | — | 2026-05-18 | |
| domain | hebsbsbzjsjshduxbs.xyz | — | 2026-05-18 | |
| domain | mlroweb.com | — | 2026-05-18 | |
| domain | qq-0732gwh22.com | — | 2026-05-18 | |
| URL | http://mlcrosoft.co.com | — | 2026-05-18 |