AmnesiaStealer is a new macOS information-stealing malware spread through ClickFix lures, including fake GitHub download pages, and it can steal passwords, browser data, keychain items, and cryptocurrency wallet information. Its standout feature is a stream_module that clones a victim’s Chromium profile and lets attackers interact live with authenticated browser sessions through a hidden headless browser. #AmnesiaStealer #ClickFix #Jamf
Keypoints
- AmnesiaStealer targets macOS users through ClickFix campaigns.
- It is delivered via a fake GitHub page and a password-protected ZIP archive.
- The malware steals browser profiles, passwords, keychain data, Apple Notes, documents, and wallet information.
- Its stream_module enables live remote control of authenticated Chromium sessions.
- Jamf says it may be the first macOS malware to combine cloned Chromium profiles with CDP-based browser control.