Exploited in the wild macOS malware AmnesiaStealer Apple phishing
AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions
CVE Tools coverage
Researchers have identified active exploitation of a new Rust-based macOS information stealer called AmnesiaStealer, which is distributed through malicious ClickFix campaigns involving counterfeit GitHub download pages. The malware utilizes a three-stage infection chain that includes leveraging the TCC bypass vulnerability CVE-2020-9771 to harvest sensitive data from Chromium-based browsers and Apple Notes. Notably, the tool allows attackers to establish live, interactive control over victim browser sessions via a headless module, distinguishing it from other similar macOS threats.