AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions

https://www.securityweek.com/wp-content/uploads/2025/02/MacOS-Mac-malware-Apple.jpeg

A multi-stage Rust-based macOS information stealer has been distributed through a counterfeit GitHub download page in recent ClickFix attacks, Jamf reports.

The fake download page lures victims into pasting a command into Terminal, which leads to the newly discovered AmnesiaStealer being installed.

As part of a three-stage infection chain, a shell script runs to fetch and execute the payload, the infostealer harvests data, and a third module is run on command to provide interactive control over the victims’ browsers.

“Its objectives overlap with families such as Atomic (AMOS), MacSync and CrashStealer. Three traits set it apart: a builder-driven configuration, OS version-branched logic that reaches for patched macOS bypasses, and the remote-control second stage,” Jamf notes.

After execution, the malware performs reconnaissance, prompts the user to provide their login password and validates it locally, copies login and data-protection keychains, and harvests Chromium-based browser databases, Apple Notes, and documents.

AmnesiaStealer also attempts...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more