FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

AmnesiaStealer: macOS Malware Leveraging Fake GitHub Lures for Live Browser Hijacking

AmnesiaStealer is a sophisticated Rust-based infostealer targeting macOS users via "ClickFix" social engineering on counterfeit GitHub repositories. The malware utilizes a multi-stage execution flow to exfiltrate macOS Keychain data, saved passwords, and browser cookies from Safari and Chromium-based browsers. Critically, it leverages the Chrome DevTools Protocol (CDP) to grant remote operators live, real-time control over active browser sessions, allowing attackers to bypass multi-factor authentication (MFA) and facilitate immediate account takeover by manipulating the victim's authenticated browser instance.

MedusaHVNC Trojan: Stealthy Browser Hijacking via Windows Hidden Desktops

MedusaHVNC is a sophisticated Remote Access Trojan (RAT) that leverages the legitimate Windows Hidden Desktop API to create an invisible parallel workspace. This allows the malware to instantiate and control browser sessions independently of the primary user interface, enabling the hijacking of active, authenticated sessions for the exfiltration of cookies, credentials, and private data. By operating outside the primary desktop's visual and monitoring scope, MedusaHVNC bypasses traditional user-perceived anomalies and evades many EDR/AV tools that focus on primary UI interaction and window activity.

Adaptive Phishing Kits and BlueKit Browser-in-the-Middle BitM Frameworks

Modern phishing campaigns are deploying adaptive kits that utilize client-side JavaScript fingerprinting (User-Agent, OS, screen resolution) to serve device-specific HTML/CSS templates, increasing social engineering success rates. These kits employ Browser-in-the-Middle (BitM) frameworks, such as BlueKit, and OAuth/OIDC Device Code phishing to intercept real-time session cookies and MFA tokens, effectively bypassing traditional multi-factor authentication. Attackers utilize DNS query manipulation and environment-aware checks to evade automated sandboxes and security crawlers. The impact is a significant reduction in MFA efficacy and increased detection difficulty for legacy indicator-based security tools.


LINK COPIED TO CLIPBOARD