Mac Malware Can Control Active Browser Sessions
A routine-looking download can turn into a much bigger problem for Mac users. Jamf Threat Labs found an AmnesiaStealer campaign reaching macOS through a fake software download and capable of keeping attackers connected to browser sessions after infection. Researchers say the added access can extend the intrusion beyond the malware’s initial data theft. An attack begins with a user-run Terminal command, but its more unusual stage comes later, after AmnesiaStealer is already inside the system. A fake download opens the door on macOS Jamf Threat Labs traced the campaign to a counterfeit GitHub-style page offering a macOS download. Visitors are instructed to copy an encoded command into Terminal, using a ClickFix attack chain that relies on the target to execute the malicious instructions. Running the command triggers a shell script that downloads and launches AmnesiaStealer. The malware also attempts to obtain the user’s login password as it prepares to collect information from the system. Turning stolen data into browser access AmnesiaStealer first collects information stored on the infected device. Jamf found it targeting browser data and the macOS …








