Security researchers have identified a new macOS malware campaign that leverages fake GitHub pages to deceive users into compromising their systems. Dubbed ‘AmnesiaStealer,’ this malware employs a multi-stage attack to extract sensitive information from infected Macs.
The attack initiates when users visit a counterfeit GitHub page that instructs them to execute a command in the Terminal. This action triggers the download and installation of the malicious software. Once installed, AmnesiaStealer presents a fraudulent installer prompt, requesting the user’s Mac login password. Upon obtaining this credential, the malware gains access to the system’s Keychain, enabling it to harvest stored passwords and other confidential data.
Beyond Keychain data, AmnesiaStealer targets browser information from Safari and Chrome, including cookies and saved logins. It also seeks to extract data from Apple Notes, Telegram sessions, and personal files stored on the device. Notably, the malware can clandestinely launch a controllable instance of the victim’s browser, providing attackers with access to accounts that are already authenticated.
It’s important to note that this attack does not exploit any unknown vulnerabilities within macOS. Instead, it relies on social engineering tactics, persuading users to execute commands and provide their passwords, thereby granting the malware the necessary permissions to operate.
In recent years, macOS has seen a rise in malware campaigns employing similar strategies. For instance, the ‘CrashStealer’ malware posed as an Apple tool to steal passwords and data, while ‘ClickLock’ rendered Macs unusable until users surrendered their passwords. These incidents underscore the evolving nature of threats targeting macOS users.
To mitigate the risk of such infections, users should exercise caution when prompted to execute commands from unverified sources. It’s advisable to download software exclusively from trusted and official websites. Additionally, maintaining up-to-date security software and regularly monitoring system activity can help detect and prevent unauthorized access.
As cyber threats continue to evolve, it’s imperative for users to remain vigilant and informed about the latest attack vectors. By adopting proactive security measures and staying abreast of emerging threats, individuals can better protect their systems and personal information from malicious actors.