Mac users beware: this new sneaky infostealer malware disguises itself as official Apple tools to lure victims.


  • SentinelOne discovers a new variant of the macOS information stealer SHub called Reaper, spread via typosquatted WeChat and Miro domains
  • The malware disguises itself with fake Apple and Google update components, establishing persistence and backdoor access.
  • Reaper targets browser credentials, crypto wallets, password managers and sensitive documents, with signs that Russian-speaking operators are avoiding CIS systems

Cybersecurity researchers at SentinelOne have discovered a new variant of the popular SHub macOS infostealer malware called “Reaper.”

In a new report, SentinelOne said it observed typosquatted domains spoofing popular apps WeChat (a popular Chinese messaging and social media app) and Miro (an online visual collaboration and whiteboarding platform).

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top