Stealer Spoofs Google, Microsoft & Apple, Then Backdoors macOS
SHub Reaper stealer spoofs Google, Microsoft, and Apple to backdoor macOS systems via fake installers.
Run WeChat?
Get an email when a reviewed story names WeChat, usually within the hour.
Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works
Summary
SHub Reaper is a new stealer malware that impersonates legitimate software installers (WeChat, Miro) from Google, Microsoft, and Apple to trick users into downloading compromised packages. The malware represents a tactical shift from ClickFix social engineering toward direct AppleScript-based execution for macOS backdoor deployment. This campaign demonstrates how threat actors are evolving distribution methods to bypass user skepticism through trusted brand spoofing.
Indicators of Compromise
- malware — SHub Reaper