“macOS is becoming an increasingly attractive target, and the tools used by attackers are getting better and more professional”: Experts warn that “convincing” fake CleanMyMac installations target Apple users to drain crypto wallets


  • Fake CleanMyMac Utility Spreads SHub Information Stealer
  • Attack tricks users into pasting terminal commands
  • Malware Steals Credentials, Cryptocurrencies, and Persists Through a Backdoor

A fake Mac utility program tricks users into installing information-stealing malware that exfiltrates passwords, sensitive files and even money, experts have warned.

Security researchers Malwarebytes said the program was part of a larger, highly sophisticated campaign that also included a custom website, reputable brand spoofing, a loader, and the good old ClickFix approach.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top