Interestana
Home/News/AmnesiaStealer macOS Malware Hijacks Browser Sessions
BleepingComputer3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

AmnesiaStealer macOS Malware Hijacks Browser Sessions

A new information-stealing malware identified as AmnesiaStealer has been discovered targeting macOS users, employing a novel ClickFix attack vector to compromise systems. This sophisticated malware is designed to exfiltrate sensitive data by hijacking active browser sessions, a capability significantly enhanced by its integrated streaming module. This module allows attackers to remotely control the victim's web browser in real-time, enabling them to navigate websites, input credentials, and potentially execute further malicious actions without the user's knowledge or consent.

The ClickFix attack, a primary method of initial infection for AmnesiaStealer, leverages social engineering tactics to trick users into downloading and executing malicious files disguised as legitimate software updates or utilities. Once installed, the malware establishes a persistent presence on the infected macOS device. The core functionality of AmnesiaStealer revolves around its ability to steal a wide range of sensitive information. This includes browser cookies, saved login credentials, autofill data, and cryptocurrency wallet information. The malware systematically searches for and collects this data from various web browsers commonly used on macOS, such as Safari, Chrome, and Firefox.

What distinguishes AmnesiaStealer from other information stealers is its advanced remote control feature. The streaming module enables attackers to establish a live, interactive session with the victim's browser. This means an attacker can see what the victim sees in their browser and directly manipulate it. This capability could be used for a variety of malicious purposes, including conducting further phishing attacks by guiding the user to fake login pages, performing unauthorized transactions, or even using the compromised browser as a pivot point to access other sensitive applications or data on the infected machine. The malware's ability to stream browser activity also aids attackers in verifying the stolen information and identifying high-value targets.

Researchers have noted that AmnesiaStealer's modular design allows for potential future expansion and adaptation, making it a persistent threat in the macOS malware landscape. The developers behind AmnesiaStealer appear to be actively updating and refining its capabilities, indicating a commitment to its ongoing development and deployment. The implications of such malware are significant, as it not only leads to direct financial loss through stolen credentials and cryptocurrency but also poses a severe risk to user privacy and data security. The sophisticated nature of its remote control functionality underscores the evolving tactics employed by cybercriminals to exploit vulnerabilities and compromise user systems.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next