惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
N
Netflix TechBlog - Medium
P
Proofpoint News Feed
D
Docker
J
Java Code Geeks
L
LangChain Blog
Microsoft Security Blog
Microsoft Security Blog
The GitHub Blog
The GitHub Blog
I
InfoQ
Stack Overflow Blog
Stack Overflow Blog
云风的 BLOG
云风的 BLOG
Engineering at Meta
Engineering at Meta
MongoDB | Blog
MongoDB | Blog
月光博客
月光博客
T
Tailwind CSS Blog
M
MIT News - Artificial intelligence
Blog — PlanetScale
Blog — PlanetScale
Google DeepMind News
Google DeepMind News
腾讯CDC
罗磊的独立博客
U
Unit 42
爱范儿
爱范儿
Vercel News
Vercel News
MyScale Blog
MyScale Blog

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers
New Password Stealer Spoofs Apple, Google And Microsoft I...
Davey Winder · 2026-05-18 · via Forbes - Innovation
Apple Mac Book Pro

macOS infostealer spoofs Apple,Google and Microsoft in a single attack.

NurPhoto via Getty Images

Just because you use macOS does not mean you are off of cybercriminals’ radar. One particularly clever new threat, a variant of an already well-known and dangerous password stealer, has been found to change disguises at every stage of the infection chain. Security researchers have now warned that it uses a payload hosted on a typo-squatted Microsoft domain, is delivered as an Apple security update, and even adds persistence to the exploit mix via a spoofed Google Software Update directory. Here’s what you need to know about the latest SHub Reaper multi-stage attack chain.

ForbesSeniors Targeted—FBI Issues Cyber Attack Advice For The Over 60sBy Davey Winder

The Latest SHub Reaper macOS Password Stealer Dissected

While Microsoft is stealing the security limelight for all the wrong reasons right now, with an actively exploited Exchange Server zero-day confirmed and an angry Windows hacker dropping more exploits at a rate of knots, macOS users should not be complacent.

While there are fewer active security threats facing users who have adopted an Apple ecosystem rather than a Microsoft one, that by no means implies that there are none. From the Atomic macOS Stealer replete with an embedded backdoor, to the Infiniti Stealer targeting passwords, bringing the ClickFix threat to the Mac. Now you can add another macOS “stealer” to the mix in the shape of SHub Reaper, traditionally also using the ClickFix commands to terminal technique, but, according to a May 18 analysis from SentinelOne research engineer Phil Stokes, this new variant “uses a delivery mechanism that bypasses Terminal entirely and sidesteps Apple’s Tahoe 26.4 mitigation for those attack flows.”

Reaper uses fake WeChat and Miro installers as lures, Stokes confirmed, “but what stands out is the way the infection chain shifts its disguise at each stage.”

This latest Reaper malware build also demonstrates that the criminal operators behind the SHub infostealer threat are “extending their malware beyond straightforward credential and wallet theft,” Stokes warned in the detailed and highly technical report, “Alongside an AMOS-style Filegrabber and chunked uploads” Stokes said, “the variant also installs a persistent backdoor, giving the operators more ways to steal data or pivot to other malicious installs after the initial compromise.”

MORE FOR YOU

ForbesMy Password Has Been Stolen—What Happens Next?By Davey Winder

But most importantly of all, macOS users need to be aware of how the SHub Reaper threat actors are employing that infection chain by layering familiar brands across multiple stages of the same singular attack. “A fake WeChat or Miro installer, delivery from a typo-squatted Microsoft domain, execution disguised as an Apple security update, and persistence hidden in a fake Google Software Update path,” are all employed, Stokes confirmed.

If you don’t want your password and other data stolen by SHub Reaper, then you are advised not to run scripts or installers from untrusted sites, don’t take the “security update is needed so click here” bait, check to ensure the URLs of sites you visit are the real deal rather than close copies, and only use the Mac App Store rather than clicking through from social media or email.