AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS
Overview
Researchers have identified a new information-stealing malware targeting macOS users, named AmnesiaStealer. This Rust-based malware can hijack Chromium web browsers, allowing attackers to access and steal session data. AmnesiaStealer is distributed through a fake GitHub download page that pretends to offer legitimate software, misleading users into downloading it. This poses a significant risk to users who might unknowingly provide sensitive information, as attackers gain live control of their browsing sessions. It’s crucial for users to be vigilant about where they download software and to ensure they are using official sources to avoid falling victim to such scams.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Chromium web browsers on macOS
- Action Required: Users should avoid downloading software from unofficial sources and verify the authenticity of websites before downloading any files.
- Timeline: Newly disclosed
Original Article Summary
Cybersecurity researchers have disclosed details of a new macOS-oriented, Rust-based information stealer called AmnesiaStealer that's capable of hijacking Chromium web browsers to steal session data. The multi-stage stealer is spread via a counterfeit GitHub download page titled "Download for macOS" and claims to be from a verified publisher. The page employs a ClickFix-style lure that
Impact
Chromium web browsers on macOS
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Users should avoid downloading software from unofficial sources and verify the authenticity of websites before downloading any files.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to macOS, Apple, Malware.