SHub Reaper Stealer macOS Backdoor Campaign | MSSP Advisory
HighCredible Report
DateMay 19, 2026
📋Executive Summary
SHub Reaper stealer targets macOS systems through fake WeChat and Miro installer packages that spoof legitimate Google, Microsoft, and Apple branding. The malware uses Apple script-based execution to steal credentials and establish backdoor access, representing a shift from previous ClickFix social engineering tactics to more sophisticated macOS-specific attack vectors.
⚠️Why It Matters for MSSPs
Your Mac users running RMM agents or accessing client networks become infection vectors that compromise both your operational security and client environments. Every client with mixed Windows and macOS environments needs immediate awareness that their Mac users face targeted credential theft designed to bypass traditional endpoint protection focused on Windows threats.
📬
Get notified when client-ready advisories like this are published each week.
Join the MSSP Watchlist →🏷️Threat Category
Identity Access
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.