By Davey Winder
Publication Date: 2026-05-18 14:29:00
macOS infostealer spoofs Apple,Google and Microsoft in a single attack.
NurPhoto via Getty Images
Just because you use macOS does not mean you are off of cybercriminals’ radar. One particularly clever new threat, a variant of an already well-known and dangerous password stealer, has been found to change disguises at every stage of the infection chain. Security researchers have now warned that it uses a payload hosted on a typo-squatted Microsoft domain, is delivered as an Apple security update, and even adds persistence to the exploit mix via a spoofed Google Software Update directory. Here’s what you need to know about the latest SHub Reaper multi-stage attack chain.
The Latest SHub Reaper macOS Password Stealer Dissected
While Microsoft is stealing the security limelight for all the wrong reasons right now, with an actively exploited Exchange Server zero-day confirmed and an angry Windows…