CVE Tools
Back to feed
Exploited in the wild macOS malware AmnesiaStealer Apple phishing

AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions

SecurityWeek·By Ionut Arghire··2 min read
CVE Tools coverage

Researchers have identified active exploitation of a new Rust-based macOS information stealer called AmnesiaStealer, which is distributed through malicious ClickFix campaigns involving counterfeit GitHub download pages. The malware utilizes a three-stage infection chain that includes leveraging the TCC bypass vulnerability CVE-2020-9771 to harvest sensitive data from Chromium-based browsers and Apple Notes. Notably, the tool allows attackers to establish live, interactive control over victim browser sessions via a headless module, distinguishing it from other similar macOS threats.