AmnesiaStealer malware grants attackers hidden control of Mac browsers
Key Takeaways A new macOS info-stealing malware, AmnesiaStealer, offers attackers live control of compromised web browsers. The malware bypasses multi-factor authentication by hijacking active,...
Key Takeaways
- A new macOS info-stealing malware, AmnesiaStealer, offers attackers live control of compromised web browsers.
- The malware bypasses multi-factor authentication by hijacking active, authenticated browser sessions.
- It is distributed via a social engineering technique called ClickFix, which tricks users into executing malicious Terminal commands.
- AmnesiaStealer targets credentials, browser data, Apple Notes, Telegram sessions, documents, cryptocurrency wallets, and keychain information.
- The threat establishes persistence through a disguised LaunchDaemon, making a one-time execution a long-term compromise.
Cybersecurity researchers have uncovered a sophisticated macOS information stealer, dubbed AmnesiaStealer, that goes beyond typical credential theft. This new malware empowers attackers with silent, real-time control over authenticated browser sessions on infected Mac systems, effectively turning a victim’s machine into an undetected conduit to sensitive accounts like email, business applications, and cryptocurrency services.
The distribution of AmnesiaStealer leverages a social engineering tactic known as ClickFix. This method manipulates users into voluntarily executing a command. Victims are directed to deceptive GitHub download pages, where they are instructed to copy and paste a specific command into their Terminal application. This command then initiates the download and execution of a multi-stage, Rust-based payload, while simultaneously removing any traces of the installation to evade detection.
According to a Polyswarm report, the malware is designed to harvest a broad spectrum of sensitive data. This includes login credentials, comprehensive browser records, Apple Notes, Telegram session data, various documents, browser-related cryptocurrency wallet information, and material from the macOS keychain. Analysts at Polyswarm highlight this as a significant evolution in malware capabilities, moving from mere data exfiltration to active, interactive exploitation of authenticated browser sessions.
The danger posed by AmnesiaStealer is particularly severe because it can bypass multi-factor authentication (MFA). While a stolen password can often be reset, an active browser session already satisfies MFA requirements, granting attackers immediate access without further prompts. Furthermore, the malware establishes a stealthy LaunchDaemon for persistence, ensuring that a single, ill-advised Terminal command can lead to a prolonged compromise of the system.
AmnesiaStealer’s Covert Browser Control
The defining characteristic of AmnesiaStealer is its advanced second-stage browser streaming module. Following an initial data collection phase, threat actors can activate a component that duplicates the victim’s browser profile and initiates it within a hidden, headless Chromium session. Crucially, the user’s visible browser remains operational, often displaying no signs of malicious activity.
This module communicates via the legitimate Chrome DevTools Protocol, typically used for debugging purposes. In the hands of an attacker, this protocol grants full control, enabling them to navigate websites, manage tabs, simulate keyboard and mouse inputs, and observe browser output in real time. The malware supports seven different Chromium-family browsers.
This level of access fundamentally alters the value of an infection. Instead of sifting through exfiltrated data post-breach, attackers can directly interact with live, authenticated sessions. This allows them to view account pages, complete sign-in processes, export decrypted cookies, or even import cookies into a separate session. This mirrors the broader threat seen in macOS credential theft, where stolen browser data facilitates comprehensive account takeover.
The initial stage of AmnesiaStealer targets sixteen Chromium-based browsers, meticulously gathering cookies, login databases, browsing history, bookmarks, extensions, local state data, preferences, and other associated artifacts. It also attempts to retrieve each browser’s Safe Storage key from the login keychain, which could aid the subsequent module in decrypting and accessing protected browser information.
AmnesiaStealer is designed for adaptability, with its operation varying based on the specific campaign and macOS version. Researchers have observed encrypted, build-specific settings and execution paths, along with attempts to bypass older privacy controls that Apple has already patched. This inherent flexibility means that behavioral indicators, rather than static file signatures, are crucial for effective detection by defenders.
ClickFix Lure Elevates Risk
The initial infection vector for AmnesiaStealer bypasses software vulnerabilities, instead relying on social engineering to exploit user trust. A convincing, fake download page mimics legitimate developer sites, replacing standard installation procedures with instructions to execute Terminal commands. Previous macOS ClickFix attack reports illustrate how attackers exploit common verification or download prompts to trick users into self-installing malware.
Upon execution, AmnesiaStealer first profiles the Mac system and then displays an Installer-themed prompt, requesting the user’s password. It validates this password locally, unlocks the login keychain, bundles all stolen data, and transmits it to attacker-controlled infrastructure. Following this, it establishes its persistence mechanism and meticulously deletes any forensic artifacts.
Users should be extremely wary of any webpage, regardless of its apparent legitimacy (e.g., GitHub, CAPTCHA, or support pages), that instructs them to paste commands into Terminal. Recent <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/21a81b4e-f3ac-43aa-86e4-2e5cc35b04b5/AmnesiaStealer-Gives-Hackers-Hidden-Control-of-Logged-In-Browsers-on-Macs.pdf?AWSAccessKeyId=ASIA2F3EMEYEYJOHNHCQ&Signature=XFEQ%2B1jSLaIOumELXlIwPhI34HA%3D&x-amz-security-token=IQoJb3JpZ2luX2VjECIaCXVzLWVhc3QtMSJHMEUCICo97aE0YXWdogdYRNkcjRkHf3AXH3UvEjJqmv%2BJB6YqAiEA5pAO0E16XyCGaJQCp2Zy2HjwlXvbwSEHM7YsqkPuHGMq%2FAQI6%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDBo%2B8hx9Z754GqNVdSrQBHF9q%2BtVxXRtF%2BMxRyUJIWkeI1cpRsBVrv3Htrc0MNfDR7pqd0pluai3ocdzAFO8NVe4Aq7W6nAvCdl97WxGzE5wbSLp8cQCgcAKiP%2B3LOFBs6IpiXkiSSs%2BFF28L4RHarxVZ0vlIrXnZjIIpAEukudWpNB31DCXHl7fJiSzvYtov1252WOTHZ8tOz6Fh%2FicjTHeWrH4W7YWttqDRTwKOOHtp3NymsfMNKUuhWvjKsvEXOkVotjjl%2F9GG48OVrEcQmyAxCtAI02haEqNSPn0RquQTbPIBnu8V6VRMD6S8uXH8tR29ihuwrj9kx9wFOYs%2FZBFABFp8%2FrrFq3F8oL9nEmDkf8q8Tv3S1CGZ6vechnVk75KdB0XMoKKEHgjnIS1RYWEc7AzE5405C2lhSLU70ve6MGnRsix6PIYDXgF7AfyHRK9NGhm8lQp4zuDF%2FG%2FWRtiz%2Fe5vzO1NFy38sI4QdeQY0TxovM5qQg3rgLf7RKr845R%2FLpeiVqEy6QYwIE4i0x2%2BTHjNL1ZTKnOIvSnNYU90ixGHeV7GkxQtmLxoWtouEyqRRwpmlwQCeoS6Z%2F11c4aHgFLlU8SnfqwvjqvNr6hDCUe2eozPRCXqKC%2B2tQBGoevSP3g%2Fad%2BeTf3QeM189pEmCUNKWdZXfkeplGiWvdgqL4F65PBHF4WKjKoo4B1GEGujMougjz%2BUoac67GEgmIcisS7Y%2FvfCjCIQ%2BFY1sXCSPaPKeqVkCEVx5RFyC8Vi%2BNbQV2IG
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.