started · updated
Cybersecurity researchers identify new macOS and Android malware threats
Security researchers have identified two distinct malware threats targeting macOS and Android users.
Jamf researchers discovered AmnesiaStealer, a Rust-based malware for macOS that spreads via ClickFix social engineering attacks. Attackers use fake GitHub pages to trick users into running malicious commands through the Terminal. Once installed, the malware can steal passwords, browser data, and active sessions, while also targeting content from Apple Notes and Telegram. Notably, the malware mutes the computer's sound to prevent users from hearing system noises during data theft.
Separately, Group-IB researchers identified a new Android threat combining the WindRelay malware with the SpyNote remote access tool. In this scheme, attackers pose as bank employees during phone calls to trick victims into installing SpyNote. Once control is established, they deploy WindRelay, which acts as a fake NFC payment terminal. This allows criminals to capture credit card data in real-time as victims hold their cards near their phones, enabling immediate fraudulent purchases or ATM withdrawals.