Reaper is a macOS infostealer variant in the SHub family. It uses counterfeit installers for applications such as WeChat and Miro, brand impersonation involving Apple, Microsoft, and Google, and typo-squatted download sites to entice victims into launching a pre-populated malicious AppleScript in macOS Script Editor. The concealed script downloads further components, displays deceptive security-update prompts, and requests the user’s macOS password. Reaper targets browser data, stored credentials, password-manager data, macOS Keychain and iCloud-related information, cryptocurrency wallet data, Telegram session data, developer configuration files, and potentially valuable documents from user-accessible locations. It can also modify supported desktop cryptocurrency-wallet applications to enable continued theft. The malware establishes persistence by masquerading as Google software-update components and registering a LaunchAgent that periodically beacons to attacker infrastructure. The beacon can retrieve and execute additional code in the compromised user’s context, providing a persistent backdoor. Reaper includes victim profiling and anti-analysis behavior, including avoidance of likely CIS-region systems, debugger interference, and console tampering.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
The updated build, now called Reaper, spreads through fake websites that impersonate popular software... It uses a fake webpage to silently open your Mac’s Script Editor, pre-loaded with malicious code, and all a user has to do is click one button to unknowingly launch the infection.
Known as “IoT Troop” or “Reaper”, this threat targets IoT devices by exploiting vulnerabilities on internet-connected devices such as IP cameras and consumer grade routers.
Reaper drops a highly persistent User LaunchAgent script onto the host... The native LaunchAgent configuration is designed to trigger this GoogleUpdate beacon script automatically every 60 seconds, logging system details and checking in with the C2 server’s /api/bot/heartbeat endpoint.
the fake websites use a specific internet link format ( applescript:// ) to automatically open the built-in macOS Script Editor app. The hackers hide the malicious code inside the app by using extensive ASCII art and arbitrary whitespace injection to obfuscate the functional script sequences below the visible scroll boundary
The hackers hide the malicious code inside the app by using extensive ASCII art and arbitrary whitespace injection to obfuscate the functional script sequences below the visible scroll boundary of the graphical user interface.
the campaign distributing an updated version of SHub Stealer under the build tag Reaper... attackers used fake download pages for popular apps such as WeChat and Miro to target victims.
If the server returns a “code” payload, the script decodes it, writes it to /tmp/.c.sh , runs it with the current user’s privileges, and then deletes it.
Once the script runs, it displays a fake Apple security update message to trick the user into typing in their system password.
Earlier builds could already steal browser data, macOS Keychains, iCloud account data, and Telegram session information. The new version goes much further, now targeting Chrome, Firefox, Brave, Edge, Opera, Vivaldi, Arc, and Orion browsers, along with their extensions.
IoT malware spreads by scanning the Internet for other vulnerable devices... according to research released Oct. 20 by Chinese security firm Netlab 360, the scanning performed by the new IoT malware strain ... is not very aggressive, and is intended to spread much more deliberately than Mirai.
The malware also carries an AMOS-style Filegrabber that hunts through Desktop and Documents folders for valuable files, including .docx, .wallet, .key, .csv, .xls, and .json formats.
Once the script runs, it displays a fake Apple security update message to trick the user into typing in their system password.
Files are staged in /tmp/shub_random/ before being split into 10MB chunks and uploaded to the attacker’s server via curl.
These archives are transmitted via standard curl commands to an external command-and-control server at hebsbsbzjsjshduxbs.xyz/gate/chunk.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Early program designed to detect and remove Creeper; often described as an early antivirus tool. Its authorship is not reliably established in the content.
A macOS SHub variant that uses fake WeChat and Miro installers delivered via a typo-squatted Microsoft-themed domain, executes via AppleScript/Script Editor, establishes persistence through a fake Google Keystone LaunchAgent, steals files, browser credentials, developer keystrokes, and cryptocurrency wallet data, and maintains a persistent remote execution channel through heartbeat-delivered shell scripts.
A macOS infostealer variant that spoofs trusted brands, steals credentials, password manager data, browser data, crypto wallet data, developer files, Keychain/iCloud and Telegram data, grabs business/financial documents, injects cryptocurrency wallet applications for continued theft, and establishes persistence via a GoogleUpdate-themed LaunchAgent backdoor that can beacon to C2 and execute remote code.
macOS infostealer variant that uses fake installers and AppleScript-based social engineering to steal browser data, password manager data, cryptocurrency wallet data, Keychain and iCloud information, Telegram session data, and selected files, while also establishing LaunchAgent-based persistence and a remote code execution backdoor.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.