AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS

Summary

A new Rust-based information stealer named AmnesiaStealer targets macOS users by hijacking Chromium browser sessions to steal session data. It is distributed through a deceptive GitHub download page designed to appear legitimate and employs a "ClickFix-style" lure.

IFF Assessment

FOE

This malware is designed to steal sensitive information and grant attackers live control over user browser sessions, posing a direct threat to defenders.

Defender Context

Defenders should be aware of AmnesiaStealer as a new threat targeting macOS, particularly its method of distribution via seemingly legitimate download pages. This highlights the ongoing need for user education on safe browsing practices and the verification of software sources, especially for open-source projects.

Read Full Story →