‘macOS is becoming a more attractive target and the tools used by attackers are becoming more skilled and more professional’: Experts warn of ‘convincing’ fake CleanMyMac installations targeting Apple users to empty crypto wallets


  • Fake CleanMyMac tool spreads SHub infostealer
  • Attacks trick users into entering terminal commands
  • Malware steals credentials, crypto and continues via backdoor

A fake utility tricked MacOS users into installing an infostealer malware that exfiltrates passwords, sensitive files and even money, experts have warned.

Security researchers Malwarebytes said the program was part of a wider, highly sophisticated campaign which also included a custom website, reputable brand spoofing, a loader and the good old ClickFix approach.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top