SHub is a macOS-focused cybercriminal operation associated with infostealer activity and tracked in at least one campaign under the malware name Reaper. The actor has used social-engineering lures that impersonate Apple security updates and legitimate workplace software to obtain execution on victim systems. Observed tradecraft includes victim profiling prior to delivery, selective exclusion of users in Russia, concealed command execution through macOS Script Editor, and fake security prompts designed to induce trust and capture the user’s macOS password. Once established, SHub has demonstrated broad credential and data-theft capability against web browsers, password managers, cryptocurrency wallets, and locally stored business or financial documents. The malware has also been observed collecting image files, packaging stolen material for upload, and replacing legitimate cryptocurrency wallet applications with trojanized versions to facilitate continued monitoring and theft. In addition to infostealing, SHub has shown persistence and post-compromise functionality by creating a disguised update-like foothold and polling attacker infrastructure for follow-on code execution, effectively providing a lightweight backdoor. This indicates an evolution beyond opportunistic credential and wallet theft toward sustained access, continued surveillance, and expanded exfiltration. Known aliases and related naming include shub_operator, shub_operators, and Reaper for a fresh SHub variant.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.