LastPass warns that attackers infect Mac users with malware by using fake password managers. These malicious apps mimic trusted software and spread via misleading GitHub repositories. Mac users who install them may face serious data theft.


Overview of the Attack Campaign

Attackers set up fake apps that impersonate legitimate software, then host them in GitHub repositories. They promoted those clones with SEO tricks on Google and Bing so users would find them. Once users land on these sites, they download or get directed through “ClickFix” methods.

In these ClickFix attacks, the fake app directs users to paste a command into the Terminal. That command fetches a malicious payload—AMOS malware—stores it in /tmp via base64-encoded URLs, and installs it.


What’s AMOS and How It Works

AMOS (also called Atomic) operates as a malware-as-a-service, costing around USD $1,000/month. Its creators added a backdoor component so it can maintain access, even stealthily, once it infects a system.

Attackers added that persistent access to give themselves long-term control over compromised Macs. That lets them exfiltrate data, monitor systems, and evade detection.


Spoofed Targets & Distribution Tactics

The fake password managers impersonate over 100 well-known software tools, including 1Password, Dropbox, Adobe After Effects, Notion, and Thunderbird. They host misleading GitHub repos that appear official.

Those repositories include a “download” button linking to a different site. From there users get asked to run a Terminal command. Attackers encode the URL to make detection harder and use /tmp directory to extract and run the malware.


How Users Can Defend Themselves

To avoid falling victim, Mac users should only download software from official vendor sites. If a GitHub variant appears, verify the vendor’s legitimacy and community reviews before proceeding.

Also, never run Terminal commands you don’t fully understand. A random paste-in command may install malware. Checking software signatures, ensuring macOS versions come from trusted sources, and using reputable security tools help reduce risk.


Conclusion

LastPass warns: fake password managers infect Macs with malware through deceptive SEO and GitHub tricks. Attackers deliver the AMOS malware via ClickFix attacks, backdoor access, and impersonation. By only using trusted sources and avoiding suspicious commands, Mac users can protect themselves from this threat.


0 responses to “LastPass Warns: Fake Password Managers Infect Macs with Malware”