New infostealer malware hides on Mac disguised as official Apple tools
AI-summarised brief · reviewed before publication
Security researchers have discovered a new macOS infostealer called SHub Reaper, which disguises itself as Apple security software to steal sensitive information. The malware abuses AppleScript and legitimate system processes to hide its activity and avoid traditional malware scanning tools. SHub Reaper is a more advanced version of the SHub Stealer malware family, which has been circulating through macOS-focused campaigns for two years. It expands on previous tactics by abusing trusted macOS tools and branding to appear legitimate, allowing attackers to steal passwords, cryptocurrency wallets, and sensitive files through the `applescript://` URL scheme in Script Editor.
💡 Why It Matters
- · Reaper's ability to disguise itself as official Apple tools undermines user trust in legitimate software.
- · It highlights the evolving nature of macOS threats, which now leverage trusted system processes to evade detection.