RECENT findings by Jamf Threat Labs reveal a new macOS malware called AmnesiaStealer, which uses social engineering tactics to target Apple computers. The malware lures users to a fake GitHub page where they are tricked into executing a malicious command in the Terminal. This initiates a multi-stage infection process that allows the malware to steal sensitive data such as passwords and browser cookies. Key capabilities include credential harvesting, browser hijacking, and remote control of the user's session.
Researchers suspect the attack is conducted by Russian-speaking threat actors. Security teams should be alert for unusual Terminal activities and educate users on the risks of executing unknown commands.