Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Reaper Malware Threatens Mac Users with Browser and Wallet Attacks

Reaper Malware Threatens Mac Users with Browser and Wallet Attacks

Posted on June 5, 2026 By CWS

A new and advanced variant of the SHub Stealer malware, named Reaper, has emerged as a significant threat to Mac users, utilizing sophisticated techniques to evade detection. This iteration primarily targets browsers and cryptocurrency wallets, posing a serious risk to personal data and digital assets.

Innovative Distribution Techniques

The Reaper malware spreads through deceptive websites that mimic popular software platforms, tricking users into downloading the malicious software. Upon installation, it can extract critical data from web browsers and cryptocurrency wallets without arousing suspicion.

This variant employs a novel method to infiltrate Mac systems. Unlike previous versions that required manual script execution, Reaper automatically initiates the infection process by opening the Mac’s Script Editor with pre-loaded harmful code. A single click by the user unknowingly activates the malware.

Moonlock’s Findings on Reaper Campaign

Security researchers at Moonlock have identified this Reaper campaign, marking it as the third occurrence of the automated ClickFix technique in recent macOS malware incidents. Moonlock highlights the increasing adoption of this tactic among threat actors targeting the macOS platform.

The attackers enhance their credibility by impersonating established brands and using domains that closely resemble legitimate ones. They distribute malicious software disguised as Apple security updates and employ fake Google Software Update pathways to establish persistent backdoors in compromised systems.

Broader Target Range and Stealthy Attacks

Reaper’s capability surpasses previous SHub Stealer versions by targeting a wide array of browsers, including Chrome, Firefox, Brave, and more. It also exploits vulnerabilities in legitimate cryptocurrency wallet applications, such as Exodus and Ledger Live, to siphon funds stealthily.

This malware utilizes a file-grabbing technique to search for valuable data in common file formats, subsequently transmitting the stolen information to a remote server. Reaper ensures its persistence by masquerading as a legitimate Google update service, making it difficult to detect and remove.

Preventive Measures for Users

Protection against Reaper begins with recognizing its entry strategies, which heavily rely on social engineering. Users should be wary of webpages that trigger unexpected actions, such as opening the Script Editor or Terminal unprompted.

It is crucial to avoid inputting system passwords into unexpected prompts following software installations. For cryptocurrency holders, transferring assets to offline storage solutions is advisable. Regularly updating both the operating system and security software can enhance defenses against such threats.

Indicators of Compromise (IoCs) include typo-squatted domains and fake update links used for malware distribution. Notably, the malware creates hidden directories and employs encoded scripts to maintain a stealthy presence on infected systems.

For more updates, follow us on Google News, LinkedIn, and X, and set Cyber Security News as your preferred source for instant alerts.

Cyber Security News Tags:automated ClickFix, backdoor malware, browser attack, crypto wallet theft, cyber threat, Cybersecurity, data theft, fake software sites, Mac security, Mac threats, malware detection, malware protection, Moonlock research, Reaper malware, social engineering

Post navigation

Previous Post: Chrome 149 Update Fixes Record 429 Security Flaws
Next Post: Malicious Extensions Target AI Chat Platforms Users

Related Posts

Beware of New back-to-school Shopping Scams That Tricks Drives Users to Fake Shopping Sites Beware of New back-to-school Shopping Scams That Tricks Drives Users to Fake Shopping Sites Cyber Security News
Social Engineering Attack Compromises Popular Axios Library Social Engineering Attack Compromises Popular Axios Library Cyber Security News
Malware Found in Top OpenClaw Skill Exposes Major Security Flaws Malware Found in Top OpenClaw Skill Exposes Major Security Flaws Cyber Security News
Google Releases Urgent Chrome Security Patch for Critical Flaws Google Releases Urgent Chrome Security Patch for Critical Flaws Cyber Security News
Wikipedia Lost Legal Battle Against The UK’s Online Safety ACT Regulations Wikipedia Lost Legal Battle Against The UK’s Online Safety ACT Regulations Cyber Security News
JanaWare Ransomware Targets Turkish Users with Adwind RAT JanaWare Ransomware Targets Turkish Users with Adwind RAT Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark