A sophisticated Rust-based malware known as AmnesiaStealer has emerged, aiming at macOS users through deceptive GitHub download pages, according to security firm Jamf. This recent cyber threat has been associated with ClickFix campaigns, utilizing a multi-stage attack strategy to infiltrate systems.
Infiltration Through Fake GitHub Links
The malware campaign begins by enticing users into executing a command in the Terminal. This action triggers the installation of AmnesiaStealer on the victim’s device. The infiltration process involves a three-stage infection chain, where a shell script is used to download and execute the malicious payload.
Once installed, the malware embarks on a data-harvesting mission, gathering sensitive information from the infected macOS devices. The final stage of the attack involves an interactive module that grants attackers control over the victim’s browser sessions.
Unique Traits and Functionality
AmnesiaStealer is distinguished by its builder-driven configuration and the ability to adapt its operations based on the macOS version. It also employs a second-stage remote control feature, setting it apart from other malware families such as Atomic (AMOS), MacSync, and CrashStealer.
After deployment, the malware conducts reconnaissance, prompting users for their login passwords which it validates locally. It then proceeds to duplicate login credentials and data-protection keychains, while extracting data from Chromium-based browsers, Apple Notes, and documents.
Advanced Data Theft Techniques
This malware seeks to bypass macOS security frameworks to access Safari cookies and full disk data. It leverages an outdated TCC bypass (CVE-2020-9771), particularly effective on systems where Terminal or the malware process possesses Full Disk Access.
In cases where a remote_stream command is received, AmnesiaStealer downloads a module to clone and control the browser profile. The malware targets browsers such as Chrome, Brave, Arc, and Edge, manipulating stored Safe Storage keys to make previously saved passwords inaccessible.
The malware’s advanced capabilities include executing a stream module upon request, which uses the Chrome DevTools Protocol (CDP) to operate a headless browser. This feature allows attackers to remotely manipulate the victim’s browsing session in real-time.
Cybersecurity experts emphasize the importance of vigilance against such threats, as AmnesiaStealer represents a significant risk to macOS users due to its sophisticated techniques and ability to compromise browser and data security.
