A seemingly innocuous download can escalate into a far more significant dilemma for macOS users.
Jamf Threat Labs has identified a nefarious campaign involving AmnesiaStealer, infiltrating macOS through a fraudulent software download.
This malware enables assailants to maintain persistent access to browser sessions following initial infection. Researchers assert that such extended access could prolong intrusions beyond the malware’s primary data exfiltration.
The incursion commences with a command executed within the Terminal by the user, but the more atypical phase transpires subsequently, after AmnesiaStealer has embedded itself within the system.
A Deceptive Download Breaches macOS
Jamf Threat Labs traced the illicit activity to a spurious GitHub-style webpage that offers a macOS download. Users are directed to copy an encoded command into their Terminal, employing a ClickFix attack chain that relies upon the target’s execution of harmful instructions.
Executing this command initiates a shell script that subsequently downloads and activates AmnesiaStealer.
The malware also attempts to capture the user’s login credentials as it prepares to harvest information from the infected system.
Transforming Stolen Information into Browser Access
AmnesiaStealer initially gathers data stored on the breached device. Jamf has discovered it specifically targeting browser information and the macOS Keychain, while also eyeing Apple Notes and Telegram.
Mac infostealers have previously sought out similar data. For instance, FrigidStealer has been known to focus on browser credentials and Apple Notes.
The malware can further download an optional component referred to as stream_module. This allows for the duplication of a Chromium browser profile and the initiation of a separate browser session hidden from user view. Operators can surveil the browser’s actions and transmit keyboard or mouse inputs back to it.
Duplicated browser data can maintain an authenticated session, which means services that still recognize a current session may not prompt for reauthentication immediately.
Stolen session cookies may present comparable issues, while remote browser manipulation empowers an operator to engage with the session from the compromised device.
Work Accounts Heighten the Stakes of a Breached Device
For individuals utilizing a Mac for professional purposes, treating a potentially infected device harboring AmnesiaStealer as mere malware removal is misguided.
Existing browser sessions could encompass corporate email or cloud services, contingent upon one’s job responsibilities and access privileges.
It is imperative to disconnect the affected device from the internet and notify your IT or security personnel if it is managed by the company.
Utilize a pristine device to revoke active sessions and reset passwords for sensitive accounts. Scrutinize recent activities for any unfamiliar occurrences.
Should your position entail privileged or financial access, inform responders about which services were active or recently utilized.
Sessions associated with administrative consoles or financial platforms can wield permissions far exceeding those of a standard user account.
Credential recovery efforts should progress concurrently with endpoint investigations. Unexpected Chromium processes or replicated browser profiles can assist in determining whether the browser-control component was engaged.

Recent threats like ClickLock malware have already posed a risk of credential theft for Apple users, and AmnesiaStealer introduces yet another vector for defenders to mitigate following a security breach.
Source link: Techrepublic.com.






