SHub Stealer "Reaper" — macOS Infostealer Using applescript:// URL-Scheme Delivery, Filegrabber Module, and Google-Masquerading LaunchAgent Backdoor — Threadlinqs Intelligence
As of 2026-07-18, SHub Stealer "Reaper" — macOS Infostealer Using applescript:// URL-Scheme Delivery, Filegrabber Module, and Google-Masquerading LaunchAgent Backdoor is a high-severity malware threat attributed to SHub Stealer operators, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 26 indicators of compromise.
Threat ID: TL-2026-1475 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: SHub Stealer operators · FINANCIAL
Reaper, the newest variant of the SHub Stealer macOS infostealer family, abuses the applescript:// URL scheme to launch Script Editor with hidden malicious payloads, bypassing Apple's Terminal-based
SHub Reaper is a multi-stage macOS infostealer, the latest variant in the SHub Stealer family that has circulated in macOS-focused criminal campaigns for roughly two years. It was first documented by SentinelOne on 2026-05-18 and confirmed still active in the wild via a malware-traffic-analysis.net capture dated 2026-06-22.
The infection begins on fake installer websites impersonating WeChat and Miro, hosted on typo-squatted/lookalike domains (qq-0732gwh22[.]com, mlcrosoft[.]co[.]com, mlroweb[.]com). Rather than the increasingly detected Terminal-based "ClickFix" social-engineering pattern, these sites invoke an applescript:// URL to directly launch macOS Script Editor with a pre-populated payload. The malicious AppleScript command is padded with ASCII art and fake terms-of-service text so the actual payload sits below the visible window, and the visible portion displays a spoofed Apple XProtectRemediator update notice urging the victim to click "Run." This delivery mechanism was specifically engineered to bypass the Terminal-based mitigations Apple introduced in macOS Tahoe 26.4 for prior ClickFix-style attacks, since it never touches Terminal at all.
Once running, the AppleScript silently executes a curl command to fetch a first-stage shell script. Before proceeding, the malware performs anti-analysis/geofencing: it queries com.apple.HIToolbox.plist for a Russian keyboard layout, and if the host appears to be in a CIS region it emits a cis_blocked telemetry event to the operator's Telegram bot and exits without deploying further payloads — a deliberate operational-security control consistent with an actor based in or tied to the CIS/Russian-speaking cybercrime ecosystem.
The delivery websites themselves carry heavy anti-analysis tooling: device fingerprinting (IP, geolocation, WebGL fingerprinting, VM/VPN detection), enumeration of installed browser extensions to detect password managers (1Password, Bitwarden, LastPass) and crypto wallet extensions (MetaMask, Phantom), and developer-tools obstruction (console override, F12 interception, continuous debugger statements, a Russian-language "Access Denied" overlay if DevTools are opened). All collected telemetry is exfiltrated to a hardcoded Telegram bot rather than the primary C2, separating reconnaissance/analytics traffic from payload C2 traffic.
Once the victim runs the AppleScript, it social-engineers the user into entering their macOS account password (framed as required to "decrypt" stored data), which is captured and used to unlock Keychain. Reaper then harvests: browser data across Chrome, Firefox, Brave, Edge, Opera, Vivaldi, Arc, and Orion; desktop cryptocurrency wallets Exodus, Atomic Wallet, Ledger Live, Electrum, and Trezor Suite, plus browser-extension wallets MetaMask and Phantom; macOS Keychain and iCloud credentials; Telegram session data; and a broad set of documents.
A new Filegrabber module, resembling functionality seen in Atomic macOS Stealer (AMOS), searches the Desktop and Documents folders for files matching extensions .docx, .doc, .wallet, .key, .txt, .rtf, .csv, .xls, .xlsx, .json, and .rdp (under 2MB), plus .png images (under 6MB), subject to a 150MB total collection cap. Collected files are staged under /tmp/shub_<random>/ and zipped; if the staged archive exceeds 85MB, a helper script at /tmp/shub_split.sh chunks it into 70MB ZIP segments (/tmp/shub_mzip_*.zip) that are sequentially uploaded via curl to hebsbsbzjsjshduxbs[.]xyz/gate/chunk.
Separately, Reaper performs active cryptocurrency-wallet hijacking: it locates installed Exodus, Atomic Wallet, Ledger, and Trezor Suite applications, downloads a trojanized app.asar replacement from the C2, terminates the running wallet process, and overwrites the legitimate application bundle file with the malicious asar. To make the replacement executable under macOS Gatekeeper, it strips the quarantine extended attribute with `xattr -cr` and applies an ad hoc code signature to the tampered bundle.
Befo
Target sectors: individuals, cryptocurrency, technology, finance
Target regions: North America, Europe, Global
References
- SHub Reaper | macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain
- Malware-Traffic-Analysis.net — SHub Stealer macOS infection (2026-06-22)
- New infostealer malware hides on Mac disguised as official Apple tools
- SHub Reaper Targets macOS with Fake Brand Installers
- New macOS infostealer impersonates Apple, Microsoft, and Google in a single attack chain
- SHub macOS infostealer variant spoofs Apple security updates
- SHub Reaper: The new Mac malware spoofing Apple, Google, and Microsoft
- SHub Reaper impersonates Apple, Google, and Microsoft in one MacOS attack chain
- New Mac Password Stealer Impersonates Apple, Google And Microsoft
- Do fear the Reaper - stealer swipes macOS users' passwords, wallets, then backdoors them
- Reaper macOS Stealer Bypasses Tahoe 26.4 Defenses
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 26 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
5 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566, T1204.001, T1204.002, T1059.002, T1059.004, T1543.001, T1547.013, T1036.005, T1535, T1497.001