⤷ Title: macOS Wallet Stealer Uncovered: “Nova” Malware Replaces Ledger/Trezor Apps with Phishing Clones for Seed Theft
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 00:00:47 +0000
════════════════════════
⌗ Tags: #Malware #Cryptocurrency Theft #LaunchAgent #Ledger Live #macOS #Modular Malware #phishing #Trezor Suite #Wallet Stealer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 00:00:47 +0000
════════════════════════
⌗ Tags: #Malware #Cryptocurrency Theft #LaunchAgent #Ledger Live #macOS #Modular Malware #phishing #Trezor Suite #Wallet Stealer
Daily CyberSecurity
macOS Wallet Stealer Uncovered: "Nova" Malware Replaces Ledger/Trezor Apps with Phishing Clones for Seed Theft
A new macOS stealer (Nova) uses LaunchAgents to install a modular backdoor. Its main function is replacing legitimate Ledger/Trezor apps with phishing clones that exfiltrate seed phrases as users type.
⤷ Title: The Script Editor Trap: New macOS “Reaper” Malware Bypasses Terminal Defenses to Steal Keychains
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 07:22:37 +0000
════════════════════════
⌗ Tags: #Malware #applescript URI Scheme #Gatekeeper xattr Evasion #Keychain Exfiltration #LaunchAgent Persistence #macOS Reaper Malware #macOS Tahoe Security Bypass #Remote Access Trojan #Script Editor Exploit #SentinelOne Threat Intel #SHub Infostealer
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 20 May 2026 07:22:37 +0000
════════════════════════
⌗ Tags: #Malware #applescript URI Scheme #Gatekeeper xattr Evasion #Keychain Exfiltration #LaunchAgent Persistence #macOS Reaper Malware #macOS Tahoe Security Bypass #Remote Access Trojan #Script Editor Exploit #SentinelOne Threat Intel #SHub Infostealer
Information Security News
The Script Editor Trap: New macOS "Reaper" Malware Bypasses Terminal Defenses to Steal Keychains - Information Security News
A novel exploitation technique has surfaced on macOS, designed to deceive users via a counterfeit “security update.” The malicious payload, designated as Reaper—an advanced iteration of the SHub information stealer—no longer relies on social...
⤷ Title: Bypassing Terminal Protections: New SHub “Reaper” Variant Abuses AppleScript to Loot macOS Endpoints
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 22 May 2026 08:03:04 +0000
════════════════════════
⌗ Tags: #Malware #AppleScript Exploit #crypto wallet theft #Cyber Security #Filegrabber #infosec #LaunchAgent Persistence #macOS Infostealer #Reaper Build #SentinelOne #SHub Stealer #Tahoe 26.4 Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 22 May 2026 08:03:04 +0000
════════════════════════
⌗ Tags: #Malware #AppleScript Exploit #crypto wallet theft #Cyber Security #Filegrabber #infosec #LaunchAgent Persistence #macOS Infostealer #Reaper Build #SentinelOne #SHub Stealer #Tahoe 26.4 Bypass
Daily CyberSecurity
Bypassing Terminal Protections: New SHub "Reaper" Variant Abuses AppleScript to Loot macOS Endpoints
SentinelOne exposes the SHub Stealer "Reaper" variant. It bypasses Apple's latest Terminal paste mitigations to hijack crypto wallets and corporate documents.