{"id":679038,"date":"2026-05-18T17:37:17","date_gmt":"2026-05-18T17:37:17","guid":{"rendered":"https:\/\/www.newsbeep.com\/au\/679038\/"},"modified":"2026-05-18T17:37:17","modified_gmt":"2026-05-18T17:37:17","slug":"new-mac-password-stealer-impersonates-apple-google-and-microsoft","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/au\/679038\/","title":{"rendered":"New Mac Password Stealer Impersonates Apple, Google And Microsoft"},"content":{"rendered":"<p><img decoding=\"async\" class=\" top-image\" src=\"https:\/\/www.newsbeep.com\/au\/wp-content\/uploads\/2026\/05\/1779125837_852_0x0.jpg\" alt=\"Apple Mac Book Pro \" data-height=\"2225\" data-width=\"3338\" fetchpriority=\"high\" style=\"position:absolute;top:0\"\/><\/p>\n<p>macOS infostealer spoofs Apple,Google and Microsoft in a single attack.<\/p>\n<p>NurPhoto via Getty Images<\/p>\n<p>Just because you use macOS does not mean you are off cybercriminals\u2019 radar. A clever new variant of a dangerous password stealer changes disguises at every stage of the infection chain. Security researchers warn it uses a payload hosted on a typo-squatted Microsoft domain, arrives disguised as an Apple security update, and hides inside a spoofed Google Software Update directory to maintain access to infected Macs. Here\u2019s what you need to know about the latest SHub Reaper multi-stage attack chain.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-1\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/16\/seniors-targeted-fbi-issues-cyber-attack-advice-for-the-over-60s\/\" target=\"_blank\" aria-label=\"Seniors Targeted\u2014FBI Issues Cyber Attack Advice For The Over 60s\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/16\/seniors-targeted-fbi-issues-cyber-attack-advice-for-the-over-60s\/\" rel=\"nofollow noopener\">ForbesSeniors Targeted\u2014FBI Issues Cyber Attack Advice For The Over 60sBy Davey Winder<\/a>The Latest SHub Reaper macOS Password Stealer Dissected<\/p>\n<p>While Microsoft is stealing the security limelight for all the wrong reasons right now, with an actively exploited <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/18\/microsoft-exchange-active-0-day-exploit-enable-emergency-mitigation-now\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/18\/microsoft-exchange-active-0-day-exploit-enable-emergency-mitigation-now\/\" target=\"_self\" aria-label=\"Exchange Server zero-day\" rel=\"nofollow noopener\">Exchange Server zero-day<\/a> confirmed and an <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/14\/microsoft-windows-alert-angry-hacker-drops-2-new-zero-day-exploits\/ \" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/14\/microsoft-windows-alert-angry-hacker-drops-2-new-zero-day-exploits\/\" target=\"_self\" aria-label=\"angry Windows hacker\" rel=\"nofollow noopener\">angry Windows hacker<\/a> dropping more exploits at a rate of knots, macOS users should not be complacent.<\/p>\n<p>While there are fewer active security threats facing users who have adopted an Apple ecosystem rather than a Microsoft one, that by no means implies that there are none. From the <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/08\/new-apple-macos-backdoor-warning-as-hackers-threaten-100-million-users\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/08\/new-apple-macos-backdoor-warning-as-hackers-threaten-100-million-users\/\" target=\"_self\" aria-label=\"Atomic macOS Stealer\" rel=\"nofollow noopener\">Atomic macOS Stealer<\/a> replete with an embedded backdoor, to the Infiniti Stealer targeting passwords, bringing the ClickFix threat to the Mac. Now you can add another macOS \u201cstealer\u201d to the mix in the shape of SHub Reaper, traditionally also using the <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/03\/27\/uh-oh-new-hack-yourself-apple-mac-attack-can-steal-your-passwords\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/03\/27\/uh-oh-new-hack-yourself-apple-mac-attack-can-steal-your-passwords\/\" target=\"_self\" aria-label=\"ClickFix commands to terminal\" rel=\"nofollow noopener\">ClickFix commands to terminal<\/a> technique, but, according to a May 18 analysis from SentinelOne research engineer Phil Stokes, this new variant \u201cuses a delivery mechanism that bypasses Terminal entirely and sidesteps Apple\u2019s Tahoe 26.4 mitigation for those attack flows.\u201d<\/p>\n<p>Reaper uses fake WeChat and Miro installers as lures, Stokes confirmed, \u201cbut what stands out is the way the infection chain shifts its disguise at each stage.\u201d <\/p>\n<p>This latest Reaper malware build also demonstrates that the criminal operators behind the SHub infostealer threat are \u201cextending their malware beyond straightforward credential and wallet theft,\u201d Stokes warned in the detailed and highly technical <a class=\"color-link\" href=\"https:\/\/www.sentinelone.com\/blog\/shub-reaper-macos-stealer-spoofs-apple-google-and-microsoft-in-a-single-attack-chain\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.sentinelone.com\/blog\/shub-reaper-macos-stealer-spoofs-apple-google-and-microsoft-in-a-single-attack-chain\/\" aria-label=\"report\">report<\/a>, \u201cAlongside an AMOS-style Filegrabber and chunked uploads\u201d Stokes said, \u201cthe variant also installs a persistent backdoor, giving the operators more ways to steal data or pivot to other malicious installs after the initial compromise.\u201d<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-2\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/08\/my-password-has-been-stolen-what-happens-next\/\" target=\"_blank\" aria-label=\"My Password Has Been Stolen\u2014What Happens Next?\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/08\/my-password-has-been-stolen-what-happens-next\/\" rel=\"nofollow noopener\">ForbesMy Password Has Been Stolen\u2014What Happens Next?By Davey Winder<\/a><\/p>\n<p>But most importantly of all, macOS users need to be aware of how the SHub Reaper threat actors are employing that infection chain by layering familiar brands across multiple stages of the same singular attack. \u201cA fake WeChat or Miro installer, delivery from a typo-squatted Microsoft domain, execution disguised as an Apple security update, and persistence hidden in a fake Google Software Update path,\u201d are all employed, Stokes confirmed.  What makes the campaign especially convincing is that each stage imitates familiar Apple, Google or Microsoft software behavior many Mac users already trust and routinely encounter.<\/p>\n<p>If you don\u2019t want your password and other data stolen by SHub Reaper, then you are advised not to run scripts or installers from untrusted sites, don\u2019t take the \u201csecurity update is needed so click here\u201d bait, check to ensure the URLs of sites you visit are the real deal rather than close copies, and only use the Mac App Store rather than clicking through from social media or email.<\/p>\n","protected":false},"excerpt":{"rendered":"macOS infostealer spoofs Apple,Google and Microsoft in a single attack. NurPhoto via Getty Images Just because you use&hellip;\n","protected":false},"author":2,"featured_media":679039,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[1337,64,63,113,20237,327320,327319,6385,2577,327318,296046,327321,105],"class_list":["post-679038","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-apple","tag-au","tag-australia","tag-google","tag-macos","tag-macos-attack","tag-macos-infosteasler","tag-malware","tag-microsoft","tag-password-stealer","tag-sentinelone","tag-shub-reaper","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/679038","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/comments?post=679038"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/679038\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media\/679039"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media?parent=679038"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/categories?post=679038"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/tags?post=679038"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}