New macOS malware turns stolen browsers into attacker-controlled sessions
Summary
A new macOS infostealer called AmnesiaStealer is targeting users through fake GitHub download pages that prompt them to run commands in Terminal. This malware steals credentials and sensitive data, and uniquely, allows attackers silent, interactive control over the victim's Chromium browser. This campaign utilizes a familiar social engineering tactic, previously seen with other macOS stealers like Atomic and MacSync.
IFF Assessment
This article describes a new and sophisticated malware that steals credentials and allows attackers to control a victim's browser, posing a significant threat to macOS users.
Defender Context
Defenders should be aware of this new macOS threat, AmnesiaStealer, and the social engineering tactics used to distribute it. Users are being tricked into executing commands via fake GitHub pages, so employee training on recognizing such phishing attempts and the risks of running unknown commands is crucial. The malware's ability to gain silent browser control highlights the need for robust endpoint detection and response (EDR) solutions and vigilant monitoring for suspicious browser activity.