macOS beware of the new malware AmnesiaStealer
MacOS Beware of the new malware AmnesiaStealer can take over the web browser in real time.
According to a report by the website Security Affairs, it mentions the detection of malware from the victim's machine, or an Infostealer called AmnesiaStealer, using a page that mimics the page of the famous digital library (Repo or Repository). But instead of using the download button to trick the victim into installing malware as usual, the fake page uses the command to launch the terminal app and paste the code it purports to install the application, but it is actually a malware installation. This method is called ClickFix, which is similar to other malware campaigns such as Atomic Stealer and MacSync.
On the functional side, the Amnesia Stealer malware body is divided into 3 steps. That is,
The first step will be running Shell scripts to download and install malware.
The second stage will be malware, which is written in the Rust language that will serve to steal the various important data contained within Apple Keychain, Web Browser, Apple Notes and Telegram.
Step three, the malware downloads a module named stream _ module to use to quietly take over the victim's web browser.
This third step is the highlight that makes this malware superior to most malware types in general. This remote _ stream command is used through the module, allowing hackers to control the live web browser in terms of keyboard input, mouse clicking, tab management, and web browsing. By copying the profile, the victim's web browser uses a hidden window, making the web browser window used by the victim unaffected and unaware that it is being smuggled by hackers. In addition, the stream _ module also uses the method of stealing the Cookies file by using a tool called Chrome Tools Devices Protocol. To send the Network.getAllCookies command to the Hidden Window Browser session (Headless Browser) to restore the Cookies that were previously decrypted (decrypted) inside RAM into plain text (Plaintext). Not only that, the module also uses stealth scripts by sending the Page.addScriptToEvaluateOnNewDocument command to customize the API key used to authenticate the identity (Fingerprint) to hide the said Headless Browser from being detected. In addition to that, it also establishes persistence on the system (Persistence) by installing itself as a LaunchDaemon in the Root level, disguised as a tool for reporting machine freezes. (Crash Report) under the name com.apple ReportCrash.agent, followed by random numerical values, allowing the malware to run continuously even if the machine is rebooted.
For the second stage of the main malware, the login password theft method is used by using a text window that claims to enter a password to install a new application (Installer). After the code is obtained, the malware confirms the validation of the local device with the directory service of the system with the dscl command. If the code is incorrect, it will display "Incorrect password." Please try again "for the victim to fill in a new password until the correct one is filled. After receiving the correct password, the code will be used to do many things on the system, such as apply to sudo-S to get a high level of permissions, and then apply to the security unlock-keychain -p command to steal information inside the Keychain and save stolen passwords in the unencrypted data format (Cleartext) on both the Staging Directory under the pwd file name and the folder. The victim's main (Home) in the file name is ~ / .pwd.
Not only that, with the login password obtained, the malware is also used to secretly read messages within Apple Notes. Using the sudo cat command, search desktop folders, Documents, and Downloads to find out documents and other information linked to the victim's Crypto Wallet, and steal information inside the web browser, such as saved passwords, cookies, website visit history, and Extensions. This malware can access up to 16 Chromium-family web browsers, in addition to malware. There is also an interesting way to deal with the Safe Storage Key of the Chrome web browser on macOS 26. If the malware is not able to retrieve it normally, it will be removed by the malware to replace it with the key that the malware already has. This method allows the malware to decrypt all the new stolen Cookies files and passwords, even if the previously saved data is inaccessible. This point is also a behavioral weakness to detect, because Chrome browsers generally do not delete the Safe Storage Key and regenerate it through the security command.
In the backyard system, such as the control server, or C2, it is equally bad that the control system is called the Amnesia Panel, which is embedded in the Root level within the domain used to send malware (Delivery Domain), which will be sent back in Russian if there is a false login, and when the malware-related URL is analyzed, it is found that the URL has the same URL structure, / d / command? T = token & b = build is distributed to different domains, but all domains are targeted back to the same IP number. This is clearly a builder that only sets up campaigns and embeds payload malware files.
# Trending # lemon 8 diary # macos # amnesiastealer # freedomhack
จากประสบการณ์การใช้งาน macOS และการติดตามข่าวสารความปลอดภัยไซเบอร์ ผมพบว่าในช่วงหลังมัลแวร์ประเภทขโมยข้อมูล (Infostealer) ได้ถูกพัฒนาขึ้นอย่างล้ำหน้าและซับซ้อนมากขึ้น โดยเฉพาะ AmnesiaStealer ที่ใช้เทคนิค ClickFix ด้วยการหลอกผ่านหน้าเพจปลอมของ GitHub และให้เหยื่อเปิด Terminal เพื่อติดตั้งโค้ดมัลแวร์ ซึ่งดูเหมือนว่าจะเหมาะกับผู้ที่มีความรู้ขั้นสูงหรือมีความระมัดระวังน้อยในการรันโค้ด ในส่วนของมัลแวร์ที่เขียนด้วยภาษา Rust ตัวนี้ นอกจากจะขโมยข้อมูลเช่นรหัสผ่าน, cookies คุกกี้, ประวัติท่องเว็บ และเนื้อหาภายใน Apple Notes แล้วยังสามารถควบคุมเว็บเบราว์เซอร์ของเราได้แบบเรียลไทม์โดยใช้โมดูล stream_module ที่ซ่อนไว้ ทำให้ผู้ใช้ไม่รู้ตัวเลยว่าเบราว์เซอร์ของตนถูกใช้งานโดยแฮกเกอร์อยู่เบื้องหลัง สิ่งที่ผมคิดว่าน่ากลัวที่สุดคือการที่มัลแวร์ตัวนี้สามารถลบกุญแจ Safe Storage Key เดิมของ Chrome บน macOS และแทนที่ด้วยกุญแจของตัวเอง ทำให้มันสามารถถอดรหัสข้อมูลใหม่ ๆ ที่ถูกเก็บในเบราว์เซอร์ได้ทั้งหมด ถึงแม้จะทำให้ข้อมูลเก่าที่บันทึกไว้เข้าถึงไม่ได้ก็ตาม เทคนิคนี้นับว่าล้ำและสร้างความยากในการตรวจจับมาก สำหรับผู้ใช้งาน macOS ทุกคน ผมแนะนำอย่างยิ่งให้ระมัดระวังไม่รันคำสั่งไหนใน Terminal ที่ไม่ได้มาจากแหล่งที่เชื่อถือได้ รวมทั้งหลีกเลี่ยงการดาวน์โหลดแอปจากแหล่งที่ไม่เป็นทางการ และควรติดตั้งซอฟต์แวร์แอนตี้มัลแวร์ที่รองรับ macOS เพื่อสแกนและป้องกันมัลแวร์เหล่านี้ สุดท้ายนี้ การตั้งรหัสผ่านที่แข็งแรงและเปลี่ยนรหัสอย่างสม่ำเสมอ รวมถึงใช้ฟีเจอร์ความปลอดภัยของ macOS เช่น FileVault และระบบยืนยันตัวตนหลายชั้น จะช่วยลดความเสี่ยงในการถูกโจมตีจากมัลแวร์ชนิดนี้ได้มากขึ้น การติดตามข่าวสารและความรู้เรื่องความปลอดภัยไซเบอร์อยู่เสมอจึงเป็นสิ่งจำเป็นสำหรับผู้ใช้ macOS ในยุคนี้ เพราะมัลแวร์ที่พัฒนาอย่าง AmnesiaStealer นั้นพร้อมจะก่อภัยอย่างร้ายแรงได้ในทุกเมื่อ
