Reaper is a name used for multiple unrelated malware strains, most notably an IoT botnet also known as IoTroop and a separate macOS SHub infostealer variant. The IoT Reaper/IoTroop malware emerged after the Mirai era as a worm-like botnet focused on compromising internet-connected devices by exploiting known vulnerabilities rather than relying primarily on default credentials. It has been associated with attacks against routers, cameras, DVRs, and other embedded Linux-based devices from multiple vendors, and researchers assessed that it borrowed some Mirai code while differing in propagation and operational behavior. Reaper was observed spreading more deliberately and stealthily than Mirai and was widely assessed as capable of building a large botnet for malicious uses such as distributed denial-of-service operations and broader post-compromise abuse of infected infrastructure.
A distinct malware strain also tracked as Reaper is a macOS infostealer within the SHub family. This variant uses brand impersonation and fake software installers to trick users into launching malicious AppleScript through Script Editor, bypassing mitigations aimed at earlier Terminal-based social-engineering chains. It steals browser data, credentials, password-manager information, cryptocurrency-wallet data, documents, and other sensitive files, and can establish persistence by masquerading as a Google software update component. The macOS Reaper variant also maintains a recurring beacon that can execute attacker-supplied code with the current user’s privileges, effectively providing a persistent backdoor in addition to its theft functions. Because the name Reaper is applied to these unrelated malware families, attribution and classification should be handled carefully and tied to platform and behavior rather than name alone.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
The updated build, now called Reaper, spreads through fake websites that impersonate popular software... It uses a fake webpage to silently open your Mac’s Script Editor, pre-loaded with malicious code, and all a user has to do is click one button to unknowingly launch the infection.
Unlike Mirai — which wriggles into vulnerable IoT devices using factory-default or hard-coded usernames and passwords — this newest IoT threat leverages at least nine known security vulnerabilities across nearly a dozen different device makers.
Before finishing its initial run, Reaper establishes persistence using a directory structure built to mimic Google’s legitimate Keystone update service. It places a base64-decoded bash script named GoogleUpdate... then registers a LaunchAgent using a property list named com.google.keystone.agent.plist . This causes the script to execute silently every 60 seconds in the background.
Reaper drops a highly persistent User LaunchAgent script onto the host... The native LaunchAgent configuration is designed to trigger this GoogleUpdate beacon script automatically every 60 seconds, logging system details and checking in with the C2 server’s /api/bot/heartbeat endpoint.
the fake websites use a specific internet link format ( applescript:// ) to automatically open the built-in macOS Script Editor app. The hackers hide the malicious code inside the app by using extensive ASCII art and arbitrary whitespace injection to obfuscate the functional script sequences below the visible scroll boundary
Before finishing its initial run, Reaper establishes persistence using a directory structure built to mimic Google’s legitimate Keystone update service. It places a base64-decoded bash script named GoogleUpdate... then registers a LaunchAgent using a property list named com.google.keystone.agent.plist . This causes the script to execute silently every 60 seconds in the background.
Before finishing its initial run, Reaper establishes persistence using a directory structure built to mimic Google’s legitimate Keystone update service. It places a base64-decoded bash script named GoogleUpdate... then registers a LaunchAgent using a property list named com.google.keystone.agent.plist . This causes the script to execute silently every 60 seconds in the background.
The hackers hide the malicious code inside the app by using extensive ASCII art and arbitrary whitespace injection to obfuscate the functional script sequences below the visible scroll boundary of the graphical user interface.
the campaign distributing an updated version of SHub Stealer under the build tag Reaper... attackers used fake download pages for popular apps such as WeChat and Miro to target victims.
If the server returns a “code” payload, the script decodes it, writes it to /tmp/.c.sh , runs it with the current user’s privileges, and then deletes it.
Once the script runs, it displays a fake Apple security update message to trick the user into typing in their system password.
Earlier builds could already steal browser data, macOS Keychains, iCloud account data, and Telegram session information. The new version goes much further, now targeting Chrome, Firefox, Brave, Edge, Opera, Vivaldi, Arc, and Orion browsers, along with their extensions.
IoT malware spreads by scanning the Internet for other vulnerable devices... according to research released Oct. 20 by Chinese security firm Netlab 360, the scanning performed by the new IoT malware strain ... is not very aggressive, and is intended to spread much more deliberately than Mirai.
The malware also carries an AMOS-style Filegrabber that hunts through Desktop and Documents folders for valuable files, including .docx, .wallet, .key, .csv, .xls, and .json formats.
Once the script runs, it displays a fake Apple security update message to trick the user into typing in their system password.
Files are staged in /tmp/shub_random/ before being split into 10MB chunks and uploaded to the attacker’s server via curl.
These archives are transmitted via standard curl commands to an external command-and-control server at hebsbsbzjsjshduxbs.xyz/gate/chunk.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A macOS SHub variant that uses fake WeChat and Miro installers delivered via a typo-squatted Microsoft-themed domain, executes via AppleScript/Script Editor, establishes persistence through a fake Google Keystone LaunchAgent, steals files, browser credentials, developer keystrokes, and cryptocurrency wallet data, and maintains a persistent remote execution channel through heartbeat-delivered shell scripts.
A macOS infostealer variant that spoofs trusted brands, steals credentials, password manager data, browser data, crypto wallet data, developer files, Keychain/iCloud and Telegram data, grabs business/financial documents, injects cryptocurrency wallet applications for continued theft, and establishes persistence via a GoogleUpdate-themed LaunchAgent backdoor that can beacon to C2 and execute remote code.
macOS infostealer variant that uses fake installers and AppleScript-based social engineering to steal browser data, password manager data, cryptocurrency wallet data, Keychain and iCloud information, Telegram session data, and selected files, while also establishing LaunchAgent-based persistence and a remote code execution backdoor.
A macOS infostealer variant that masquerades as a critical system update or workplace software, steals browser data, password manager contents, cryptocurrency wallet data, and selected documents, replaces wallet apps with trojanized versions, and establishes persistence via a hidden backdoor that polls a C2 server for further commands.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.