While also spoofing all the trusted domains Apple, Microsoft, and Google in the same attack A new infostealer variant targets macOS users by spoofing Apple, Microsoft, and Google and then then gets to work searching for victims password managers so it can steal all of their credentials and access cryptocurrency wallets such as MetaMask and Phantom. The updated SHub stealer variant is called Reaper, and it uses macOS Script Editor, pre populated with the malicious payload to execute the...

Read the full article at The Register