New AmnesiaStealer macOS malware hijacks browser sessions via remote control

New AmnesiaStealer macOS malware hijacks browser sessions via remote control
AmnesiaStealer is a new macOS information-stealing malware spread through ClickFix lures, including fake GitHub download pages, and it can steal passwords, browser data, keychain items, and cryptocurrency wallet information. Its standout feature is a stream_module that clones a victim’s Chromium profile and lets attackers interact live with authenticated browser sessions through a hidden headless browser. #AmnesiaStealer #ClickFix #Jamf

Keypoints

  • AmnesiaStealer targets macOS users through ClickFix campaigns.
  • It is delivered via a fake GitHub page and a password-protected ZIP archive.
  • The malware steals browser profiles, passwords, keychain data, Apple Notes, documents, and wallet information.
  • Its stream_module enables live remote control of authenticated Chromium sessions.
  • Jamf says it may be the first macOS malware to combine cloned Chromium profiles with CDP-based browser control.

Read More: https://www.bleepingcomputer.com/news/security/new-amnesiastealer-macos-malware-hijacks-browser-sessions-via-remote-control/