SHub is a malware family tracked across 2 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed March 10, 2026; most recent activity May 19, 2026.
A new variant of the SHub macOS infostealer, named 'Reaper', has been detected using a fake Google Software Update to maintain persistence on infected systems. This malware targets macOS users by masquerading as…
A fraudulent CleanMyMac website is deceiving macOS users into downloading SHub Stealer malware, which is designed to steal credentials and crypto wallet information. This campaign specifically targets Apple users,…