MacOS users beware of the new malware SHub Reaper.
Alarm macOS users Beware of the new malware SHub Reaper has a variety of data theft capabilities.
According to a report by the Techrepublic website, a report from the research team of SentinelOne, a company that develops enterprise cybersecurity tools that detect malware that steals data from victims, or a new Infostealer that specifically focuses on attacks on macOS users, the malware is called SHub Reaper, another subspecies in the SHub family.
This malware has the ability to steal various forms of data, such as passwords on web browsers (covering a variety of web browsers such as Chrome, Firefox, Brave, Edge, Opera, Vivaldi, Arc, and Orion), Crypto Wallet, covering a wide range of web browser extension wallets such as Exodus, Atomic, Ledger Live, Electrum, and Trezor Suite, developer settings (Developer Configuration Files), Session data, Telegram chat applications, and user information. Apple services, such as Data on Keychain and iCloud, etc., also use tools like Filegrabber to scan for business-related files with .docx, .doc, .wallet, .key, .keys, .txt, .rtf, .csv, .xls, .xlsx, .json, and .rdp. Files are also used to scan for business-related files with .PNG genus scanning tools smaller than 6MB and other smaller files smaller than 2MB. All stolen files are stored in the / tmp / shub _ zip folder. All stolen data is sent to the Extrusion and Control (Extrusion) server.
In the field of malware distribution, it starts by using social engineering or social engineering methods. By creating fake websites into the websites of famous applications such as Miro and WeChat. During downloading, the source URL of the file is a URL that mimics the infrastructure of Microsoft to avoid suspicion of the origin. After the malware is installed, the malware immediately requests permissions to access the system from the victim to avoid the ClickFix scam detection system (error fraud system, so that the victim runs the script to download and install the malware. Hackers) This is usually a trick for the victim to place the script on the Terminal app and run. In this case, the malware uses a script that starts with applescript: / / URL. The script is preloaded to the editor of macOS. This gives the victim the task of simply pressing Run and entering the password of the system. The password entered by the victim is decrypted. All passwords on the system are decrypted.
In addition, the malware has the ability to remain persistent on the system (Persistence) by using a Base64 encrypted script file named in imitation of the Google Software Update file name called GoogleUpdate. The script file is set to contact the C2 server every 60 seconds to receive malware commands and allow for the installation of additional malware, usually not only backdoor malware. This channel is also used to smuggle Exfiltration files to the server.
# Trending # Lemon 8 Howtoo # lemon 8 diary # macos # freedomhack












































































