AUTO-UPDATED

New AmnesiaStealer macOS malware hijacks browser sessions via remote control

A new macOS malware called AmnesiaStealer uses ClickFix campaigns to hijack authenticated browser sessions, allowing attackers to remotely control Chromium-based browsers and steal sensitive user data.

Key Points

  • AmnesiaStealer targets 16 Chromium-based browsers, including Google Chrome, Microsoft Edge, Brave, and Arc, to exfiltrate passwords, cookies, and cryptocurrency wallet data.
  • The malware utilizes a "stream_module" to launch a headless browser instance, enabling attackers to interact with authenticated sessions via the Chrome DevTools Protocol.
  • Attackers gain real-time control over the victim's browser, including mouse and keyboard input, while receiving a live screencast of the session.
  • Distribution occurs through fake GitHub download pages that prompt users to execute shell scripts from password-protected ZIP archives.
  • Researchers at Jamf identified that the malware shares distribution templates with previous threats like Atomic and MacSync infostealers.

Why it Matters

This malware represents a significant escalation in threat sophistication by moving beyond simple data exfiltration to live, interactive session hijacking. By operating through a headless browser, attackers can bypass traditional security measures and perform actions as the authenticated user, posing a severe risk to both personal and corporate accounts.
BleepingComputer Published by Bill Toulas
Read original