Apple Mac Malware Enables Attackers to Regain Control of Browser Activities Post

Try Our Free Tools!
Master the web with Free Tools that work as hard as you do. From Text Analysis to Website Management, we empower your digital journey with expert guidance and free, powerful tools.

A seemingly innocuous download can escalate into a far more significant dilemma for macOS users.

Jamf Threat Labs has identified a nefarious campaign involving AmnesiaStealer, infiltrating macOS through a fraudulent software download.

This malware enables assailants to maintain persistent access to browser sessions following initial infection. Researchers assert that such extended access could prolong intrusions beyond the malware’s primary data exfiltration.

The incursion commences with a command executed within the Terminal by the user, but the more atypical phase transpires subsequently, after AmnesiaStealer has embedded itself within the system.

A Deceptive Download Breaches macOS

Jamf Threat Labs traced the illicit activity to a spurious GitHub-style webpage that offers a macOS download. Users are directed to copy an encoded command into their Terminal, employing a ClickFix attack chain that relies upon the target’s execution of harmful instructions.

Executing this command initiates a shell script that subsequently downloads and activates AmnesiaStealer.

The malware also attempts to capture the user’s login credentials as it prepares to harvest information from the infected system.

Transforming Stolen Information into Browser Access

AmnesiaStealer initially gathers data stored on the breached device. Jamf has discovered it specifically targeting browser information and the macOS Keychain, while also eyeing Apple Notes and Telegram.

Mac infostealers have previously sought out similar data. For instance, FrigidStealer has been known to focus on browser credentials and Apple Notes.

The malware can further download an optional component referred to as stream_module. This allows for the duplication of a Chromium browser profile and the initiation of a separate browser session hidden from user view. Operators can surveil the browser’s actions and transmit keyboard or mouse inputs back to it.

Duplicated browser data can maintain an authenticated session, which means services that still recognize a current session may not prompt for reauthentication immediately.

Stolen session cookies may present comparable issues, while remote browser manipulation empowers an operator to engage with the session from the compromised device.

Work Accounts Heighten the Stakes of a Breached Device

For individuals utilizing a Mac for professional purposes, treating a potentially infected device harboring AmnesiaStealer as mere malware removal is misguided.

Existing browser sessions could encompass corporate email or cloud services, contingent upon one’s job responsibilities and access privileges.

It is imperative to disconnect the affected device from the internet and notify your IT or security personnel if it is managed by the company.

Utilize a pristine device to revoke active sessions and reset passwords for sensitive accounts. Scrutinize recent activities for any unfamiliar occurrences.

Should your position entail privileged or financial access, inform responders about which services were active or recently utilized.

Sessions associated with administrative consoles or financial platforms can wield permissions far exceeding those of a standard user account.

Credential recovery efforts should progress concurrently with endpoint investigations. Unexpected Chromium processes or replicated browser profiles can assist in determining whether the browser-control component was engaged.

A typewriter with a sheet of paper displaying the word INVESTIGATION in large letters.

Recent threats like ClickLock malware have already posed a risk of credential theft for Apple users, and AmnesiaStealer introduces yet another vector for defenders to mitigate following a security breach.

Source link: Techrepublic.com.

Disclosure: This article is for general information only and is based on publicly available sources. We aim for accuracy but can't guarantee it. The views expressed are the author's and may not reflect those of the publication. Some content was created with help from AI and reviewed by a human for clarity and accuracy. We value transparency and encourage readers to verify important details. This article may include affiliate links. If you buy something through them, we may earn a small commission — at no extra cost to you. All information is carefully selected and reviewed to ensure it's helpful and trustworthy.

Reported By

Souvik Banerjee

I’m Souvik Banerjee from Kolkata, India. As a Marketing Manager at RS Web Solutions (RSWEBSOLS), I specialize in digital marketing, SEO, programming, web development, and eCommerce strategies. I also write tutorials and tech articles that help professionals better understand web technologies.
Share the Love
Related News Worth Reading