Reaper macOS Infostealer Multi-Stage Attack Chain | MSSP Advisory

HighCredible Report
DateMay 19, 2026
📋Executive Summary
A new macOS infostealer called Reaper impersonates Apple, Microsoft, and Google to trick users into executing malicious code through a multi-stage attack chain. The malware targets browser data, password managers, and cryptocurrency wallets while establishing persistence on infected systems. SentinelOne researchers found this SHub variant moves away from standard ClickFix social engineering techniques toward more sophisticated delivery methods.
⚠️Why It Matters for MSSPs
Mac users in your client environments face a credential harvesting threat that specifically targets password managers and browser stores where business credentials live. Your own Mac workstations used for client access could expose stored RMM credentials, PSA logins, and client VPN certificates if compromised. Every compromised Mac becomes a pathway into client networks through stored authentication tokens.
📬

Get notified when client-ready advisories like this are published each week.

Join the MSSP Watchlist →
🏷️Threat Category
Identity Access

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.