Grafa
Reaper malware targets Mac crypto wallets
Image for illustrative purposes only. Not a real photo.

Reaper malware targets Mac crypto wallets

Share

A newly identified macOS malware strain known as Reaper is targeting cryptocurrency users by stealing wallet data, browser credentials and sensitive files through a social engineering campaign that exploits Apple's built-in Script Editor application.

The malware is distributed through fake download pages impersonating popular software such as WeChat and Miro, tricking users into launching malicious AppleScript code hidden behind deceptive prompts.

Unlike earlier attacks that relied on persuading users to paste commands into Terminal, Reaper uses AppleScript URLs to open Script Editor, allowing attackers to bypass security measures introduced in recent macOS updates.

Researchers said the malicious code is concealed using ASCII art and whitespace, making it appear harmless to users who unknowingly execute the hidden commands by clicking the play button within Script Editor.

The campaign also uses typosquatted domains designed to mimic legitimate websites and displays fraudulent Apple security update prompts that request a victim's system password to gain elevated access.

Once installed, Reaper targets cryptocurrency applications including Ledger Live, Trezor Suite and Exodus, while also harvesting credentials from browsers such as Chrome, Firefox and Edge, along with extensions including MetaMask and 1Password.

The malware can compress and exfiltrate documents, spreadsheets, wallet files and other sensitive data to remote servers before establishing persistence through a backdoor disguised as a Google Software Update directory, prompting security researchers to urge users to verify download sources and avoid entering passwords into unexpected prompts.

Frequently asked questions

Grafa is not a financial advisor. You should seek independent, legal, financial, taxation or other advice that relate to your unique circumstances.

Grafa is not liable for any loss caused, whether due to negligence or otherwise arising from the use of or reliance on the information provided directly or indirectly, by use of this platform.