A new macOS malware called AmnesiaStealer uses ClickFix campaigns to hijack authenticated browser sessions, allowing attackers to remotely control Chromium-based browsers and steal sensitive user data.
Key Points
- AmnesiaStealer targets 16 Chromium-based browsers, including Google Chrome, Microsoft Edge, Brave, and Arc, to exfiltrate passwords, cookies, and cryptocurrency wallet data.
- The malware utilizes a "stream_module" to launch a headless browser instance, enabling attackers to interact with authenticated sessions via the Chrome DevTools Protocol.
- Attackers gain real-time control over the victim's browser, including mouse and keyboard input, while receiving a live screencast of the session.
- Distribution occurs through fake GitHub download pages that prompt users to execute shell scripts from password-protected ZIP archives.
- Researchers at Jamf identified that the malware shares distribution templates with previous threats like Atomic and MacSync infostealers.