This Malware Can Hijack Web Browsers on MacOS, but You Can Protect Yourself.

In a new version of the ClickFix attack, hackers are distributing malware to macOS users capable of hijacking your sessions in Google Chrome, Microsoft Edge, and several other Chromium-based browsers. AmnesiaStealer provides remote control over your browser and access to a large amount of personal data, so you should know how to recognize this campaign and protect your device from hacking.

AmnesiaStealer hijacks your web browser on macOS.

As reported by BleepingComputer , AmnesiaStealer can copy a victim’s Chromium profile, allowing it to collect data from up to 16 Chromium-based web browsers, access authenticated sessions, and remotely control them. This means attackers can navigate websites, export or import cookies, access online portals, and intercept saved logins, history, bookmarks, extensions, and cryptocurrency wallet data. AmnesiaStealer can also intercept your macOS password and access keychain data, Apple Notes, Telegram sessions, documents, and system information.

Researchers from security firm Jamf discovered that hackers are distributing malware via a password-protected ZIP archive on a fake GitHub page and gaining this level of access when users run a command in Terminal that downloads and installs the payload. This campaign mimics previously identified Atomic and MacSync malware attacks .

You may also like

How to avoid browser hijacking attempts

The best way to protect yourself from AmnesiaStealer is to be vigilant against ClickFix attacks, which use social engineering techniques to deliver malware to your device. Common tricks include fake error messages, CAPTCHA forms, and, as in this case, command lines that install malware capable of spying on your activity, stealing your data, and taking control of your computer.

What do you think at the moment?

Attackers are counting on you believing these commands do something harmless (such as downloading legitimate software) or that you won’t understand what you’re actually doing on your device. Therefore, be extremely skeptical of any requests you find online and never execute commands in Terminal from unofficial sources. Note that the fake GitHub page used to distribute AmnesiaStealer is labeled “Verified Publisher” to gain users’ trust. Scammers will also try to impersonate legitimate companies—for example, tech support scams—so never copy and paste commands into the system dialog, even if you believe you’re interacting with a reputable company or service.

More…

Leave a Reply