A multi-stage Rust-based macOS infostealer called AmnesiaStealer is being spread through a counterfeit GitHub download page in recent ClickFix attacks. The malware steals browser data, keychains, and notes, and can also remotely control victims’ browser sessions via a headless Chrome-based stream module. #AmnesiaStealer #ClickFix #Jamf #GitHub #macOS
Keypoints
- A fake GitHub download page tricks users into running a malicious Terminal command.
- AmnesiaStealer uses a three-stage infection chain to install, steal data, and enable remote control.
- The malware targets keychains, Chromium browser databases, Apple Notes, and documents.
- It attempts TCC bypasses, installs a LaunchDaemon, and sends stolen data to a C&C server.
- The stream module uses Chrome DevTools Protocol to control a victim’s browser session interactively.
Read More: https://www.securityweek.com/amnesiastealer-macos-malware-steals-data-controls-browser-sessions/