Jamf Threat Labs has found Mac malware that steals sensitive data and secretly launches a controllable copy of the victim's Chrome or Safari installs, giving attackers a way into accounts that are already unlocked.AmnesiaStealerJamf's August 5 report describes a three-stage AmnesiaStealer infection observed in the wild. The attack begins on a counterfeit GitHub page that tells visitors to paste a command into Terminal.AmnesiaStealer then displays a fraudulent installer prompt and uses the captured Mac login password to reach Keychain, browser data, Apple Notes, Telegram sessions, and personal files.The attack doesn't rely on an unknown macOS vulnerability. The victim must run the supplied command and enter a valid password, but the final payload goes beyond the one-time collection associated with a conventional infostealer. Continue Reading on AppleInsider | Discuss on our Forums
Discussion
Be the first to comment
Add your perspective to get the discussion started.