AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS
A new macOS information stealer, dubbed AmnesiaStealer, is targeting Chromium-based browsers to steal user credentials and provide live, interactive control over victim's web sessions. Developed by a Rust-based threat actor, the stealer employs a multi-stage attack chain, including a builder-driven configuration, macOS version-specific bypasses, and a remote-control module that allows operators to drive a live, hijacked browser session. The stealer leverages techniques similar to ClickLock Stealer and utilizes a C2 server to facilitate command and control and data exfiltration.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
