Apple Mac Malware Lets Attackers Control Browser Sessions After Infection
ID: 3d731a47-d01d-5a9d-ad9d-ed1f5359e9dc
STIX ID: report--3d731a47-d01d-5a9d-ad9d-ed1f5359e9dc
Feed Name: TechRepublic Security
Jamf Threat Labs reported an AmnesiaStealer campaign targeting macOS via a counterfeit GitHub-style download that uses a user-executed Terminal command to install a shell script. The stealer collects browser data, macOS Keychain items, Apple Notes and Telegram data, and can download an optional "stream_module" to copy Chromium profiles and run a hidden browser instance that operators can view and control, potentially preserving authenticated sessions; organizations are advised to treat infected Macs as broader incidents, isolate devices, revoke sessions from clean endpoints, and reset credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
