---
title: "SHub Reaper impersonates Apple, Google, and Microsoft in one MacOS attack chain"
url: https://daily.dev/posts/shub-reaper-impersonates-apple-google-and-microsoft-in-one-macos-attack-chain-ozo7ospvr
source_url: https://www.csoonline.com/article/4174147/shub-reaper-impersonates-apple-google-and-microsoft-in-one-macos-attack-chain.html
type: article
source: "CSO Online"
published: 2026-05-20T11:54:00.548Z
updated: 2026-05-20T11:54:57.066Z
tags: ["security", "malware"]
reading_time: 4
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# SHub Reaper impersonates Apple, Google, and Microsoft in one MacOS attack chain

**[CSO Online](https://daily.dev/sources/csoonline)** · 4 min read · 0 upvotes · 0 comments

## Summary

SentinelOne researchers have detailed a new macOS infostealer variant called SHub Reaper that impersonates Apple, Google, and Microsoft across a single attack chain. Unlike earlier SHub variants that relied on Terminal-based ClickFix tactics, Reaper abuses the applescript:// URI handler to pre-populate malicious AppleScript in Script Editor, bypassing Apple's recently introduced Terminal paste protections. The malware uses fake Apple security alerts to initiate execution, Google-themed interfaces for legitimacy, and typo-squatted Microsoft domains for payload hosting. Once active, it harvests browser credentials, password manager data, Keychain data, cryptocurrency wallets (MetaMask, Phantom), and user documents. Defenders are advised to monitor for unusual Script Editor and osascript activity, suspicious LaunchAgent persistence entries, and implement web filtering against typo-squatted domains.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.csoonline.com/article/4174147/shub-reaper-impersonates-apple-google-and-microsoft-in-one-macos-attack-chain.html>

## Similar posts on daily.dev

- [Unmasking SHub Stealer: A Deep Dive into a Sophisticated macOS Info-Stealer Masquerading as GitHub Desktop](https://daily.dev/posts/unmasking-shub-stealer-a-deep-dive-into-a-sophisticated-macos-info-stealer-masquerading-as-github-d-82xajmlwf) · Faun · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/shub-reaper-impersonates-apple-google-and-microsoft-in-one-macos-attack-chain-ozo7ospvr)
