🕵️ SicherheitslückenÜber Zero-Day-Lücke: Angreifer schleusen Backdoor in Onlineshops ein(07.09.2026 um 13:16 Uhr)
⚠️ Malware / Trojaner / VirenAuch im Standby: LG-Fernseher wohl anfällig für weitreichende Spionageangriffe(08.09.2026 um 10:54 Uhr)
🕵️ SicherheitslückenMehrere Bugs beseitigt: Microsoft verteilt Notfallupdates für Windows(15.09.2026 um 08:57 Uhr)
🔧 AI Nachrichten Datenschutz bei KI: OpenAI lässt KI-Prompts von Menschen lesen(15.09.2026 um 09:06 Uhr)
🔧 AI Nachrichten GPT-6 Astra schafft Portal, verbrennt dabei rund 500 Euro an Tokens(12.09.2026 um 16:00 Uhr)
🪟 Windows TippsPerformance-Test: Windows 11 muss sich Linux geschlagen geben(13.09.2026 um 11:00 Uhr)
🕵️ SicherheitslückenÜber Zero-Day-Lücke: Angreifer schleusen Backdoor in Onlineshops ein(07.09.2026 um 13:16 Uhr)
⚠️ Malware / Trojaner / VirenAuch im Standby: LG-Fernseher wohl anfällig für weitreichende Spionageangriffe(08.09.2026 um 10:54 Uhr)
🕵️ SicherheitslückenMehrere Bugs beseitigt: Microsoft verteilt Notfallupdates für Windows(15.09.2026 um 08:57 Uhr)
🔧 AI Nachrichten Datenschutz bei KI: OpenAI lässt KI-Prompts von Menschen lesen(15.09.2026 um 09:06 Uhr)
🔧 AI Nachrichten GPT-6 Astra schafft Portal, verbrennt dabei rund 500 Euro an Tokens(12.09.2026 um 16:00 Uhr)
🪟 Windows TippsPerformance-Test: Windows 11 muss sich Linux geschlagen geben(13.09.2026 um 11:00 Uhr)

📰 IT Security Nachrichten 🕛 vor 3 Monaten 4 Min Lesezeit SECURITY-FEED
0

SHub Reaper impersonates Apple, Google, and Microsoft in one MacOS attack chain

↗ Quelle (csoonline.com)
🗣️ Stimme:
📑 Inhaltsübersicht








A newly disclosed macOS infostealer campaign is exploiting user trust in some of the biggest names in tech to slip past defenses. 





Researchers at SentinelOne have detailed a new variant of the SHub malware family, dubbed “Reaper,” that impersonates Apple, Google, and Microsoft at different stages of a single attack chain targeting Mac users. The SHub stealer family, identified two years back, previously , senior fellow at Sectigo. “This approach lowers the technical barrier for infection and demonstrates a strategic pivot toward abusing native application handlers rather than relying purely on user error.”





Fake Apple updates run hidden AppleScript





The attack starts with users pulled onto malicious websites displaying fake Apple security alerts. The pages then initiate a ClickFix workflow by instructing users to launch a supposed fix through the Script Editor, instead of the Terminal.





Rather than getting the user to copy and paste shell commands like earlier, Reaper now , into running the script themselves.





So the victims are still executing the malware themselves, but just can’t see it anymore.





SentinelOne researchers noted the malware also performs several environment and anti-analysis checks before continuing execution. Once active, the malware deploys additional payloads and establishes persistence through LaunchAgents posing as legitimate vendor files.





“Defenders should shift macOS detection from file signatures to behavior, because Reaper executes through legitimate Apple tools and drops no obvious malicious app for a scanner to catch,” said . “The payload may be hosted on a typo-squatted Microsoft domain, executed under the guise of an Apple security update, and persist from a fake Google Software Update directory.”





Once execution succeeds, Reaper starts harvesting sensitive user data. SentinelOne said the malware targets browser credentials, password managers, Keychain data, cryptocurrency wallets such as MetaMask and Phantom, messaging applications, and user documents.





Protection beyond blocking Terminal-pastes





SHub Reaper campaign’s complete abandonment of the traditional Terminal-centric infection flow appears to be tied to Apple’s recent efforts to crack down on Terminal paste abuse.





In macOS Tahoe 26.4, Apple introduced protections that display warnings when users attempt to paste potentially dangerous commands into Terminal, directly targeting the social engineering methods widely abused in ClickFix-style attacks.





“This is not an Apple security failure,” Hogue-spears said. “It is Apple’s fix working exactly as intended. The fix raised the cost of one technique; so the crew switched to another.” Apple did not immediately respond to CSO’s request for comments.





SentinelOne researchers recommended that defenders monitor for unusual Script Editor activity and investigate where “osascript” or AppleScript-related processes spawn unexpected processes or initiate outbound network connections. They also advised organizations to watch for suspicious LaunchAgent persistence mechanisms posing as legitimate Apple, Google or Microsoft components.





Additionally, Soroko suggested network-based protections. “Security teams should implement strict web filtering to intercept typo-squatted domains and monitor for anomalous invocations of the macOS Script Editor triggered directly by web browsers,” he said.


Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf csoonline.com.
↗ Original-Artikel auf csoonline.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Tension – Signal Run: Dieses kleine iPhone-Spiel macht zwei Finger zur Steuerung
1 Quelle
AirPods 5 get first preorder discount, plus 2026 Mac mini & Mac Studio savings
1 Quelle
Apple’s next wave: touch-screen MacBooks, a smart-home hub, and 14 more products
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten SHub Reaper impersonates Apple, Google, and Microsoft in one MacOS attack chain

Thematisch verwandte Begriffe: SHub, Reaper, impersonates, Apple · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...