< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

AmnesiaStealer malware targets macOS users via fake GitHub pages

Security researchers, including Jamf Threat Labs, have identified a new macOS-targeted infostealer named AmnesiaStealer. The malware is distributed through sophisticated social engineering tactics, primarily using fake GitHub pages that feature fraudulent ‘Verified Publisher’ tags to gain user trust.

AmnesiaStealer utilizes ‘ClickFix’ attacks, where users are tricked by technical pretexts or fake error messages into manually executing malicious scripts or Terminal commands. Once active, the malware—developed in the Rust programming language—targets Chromium-based browsers, including Google Chrome and Microsoft Edge. It is capable of collecting data from up to 16 different browsers, including credentials, browser profiles, and active session cookies.

The malware features a multi-stage attack logic that adapts to the specific macOS version installed on the device. A second stage allows for remote control of the infected system and includes scripts designed to patch browser-fingerprinting interfaces, preventing websites from detecting the automated access.

Entities

Chromium · GitHub · Jamf Threat Labs · macOS

Sources

about 1 month ago