AmnesiaStealer macOS Malware Hijacks Browser Sessions via Fake GitHub Lure

A newly recognized macOS infostealer referred to as AmnesiaStealer is spreading by way of a convincing pretend GitHub obtain web page, tricking Mac customers into pasting a malicious Terminal command that silently installs malware and may later grant attackers dwell, hidden management of the sufferer’s browser session.

Safety researchers at Jamf Risk Labs found the marketing campaign after recognizing a counterfeit website at github.aoitour[.]com that near-perfectly copies GitHub’s darkish theme, Octocat brand, and “Verified Writer” badge.

As a substitute of providing an actual obtain, the web page shows a “Terminal set up” field with a one-click copy button and step-by-step directions telling guests to open Terminal, paste the command, press Return, and enter their gadget password.

This social-engineering method, known as ClickFix, has additionally been used to unfold different Mac malware households like Atomic (AMOS) and MacSync, displaying that prison teams are reusing the identical misleading template throughout campaigns.

Counterfeit GitHub ClickFix Terminal Lure
Counterfeit GitHub ClickFix Terminal Lure (Picture Supply: .jamf.com)

As soon as a sufferer pastes the command, a hidden shell script quietly downloads a password-protected ZIP archive, extracts a disguised binary into the /tmp folder, strips Apple’s quarantine flag, and launches the payload earlier than deleting its personal tracks.

That is adopted by a Rust-based infostealer that profiles the machine, shows a pretend native “Installer” password immediate to seize the login credential, and makes use of it to unlock the keychain, Apple Notes, Telegram classes, browser information, and paperwork.

The malware is called after the “Amnesia Panel” backend it communicates with, and its embedded configuration is unlocked with the important thing 4mn3s1a_2o26!xK.

Spoofed macOS System Password Prompt
Spoofed macOS System Password Immediate (Picture Supply: .jamf.com)

Probably the most regarding functionality arrives in a 3rd element referred to as stream_module. Fetched solely on command from the attacker’s panel, this stage clones the sufferer’s browser profile, launches it in headless mode, and connects to the Chrome DevTools Protocol.

This provides the attacker a dwell screencast of the session together with full mouse, keyboard, and navigation management, successfully letting them function the sufferer’s logged-in browser classes, e mail, banking, and social media with out the sufferer ever seeing something change on their very own display screen, reads the Jamf Threat Labs report shared with Cyber Safety Information.

Curiously, a number of of the malware’s makes an attempt to sidestep Apple’s privateness protections depend on methods Apple patched years in the past, together with a 2020 APFS snapshot bypass.

On fashionable macOS variations like macOS 26, these makes an attempt largely fail, and the malware’s personal debug logs file the failures. Nonetheless, its core credential and browser-session theft nonetheless works successfully, particularly in opposition to superior customers who could have already got granted broader system permissions.

AmnesiaStealer illustrates a rising pattern the place attackers mix plausible phishing pages with staged, remotely triggered payloads reasonably than a single static malware file.

As a result of the preliminary an infection depends totally on tricking a person into working a Terminal command, the simplest protection is straightforward: by no means paste unknown instructions into Terminal, particularly ones sourced from unsolicited obtain prompts.

Retaining macOS up to date, enabling browser and endpoint risk safety, and treating any password immediate tied to a “software program installer” with suspicion are important precautions as this marketing campaign continues to evolve.

 Strengthen Your SOC by Accelerating Risk Detection & Fast Investigations. -> Integrate ANY.RUN With Your SOC Now.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *