Bg ShapeBg Shape
THREAT INTELLIGENCE

AmnesiaStealer: New macOS Infostealer Hijacks Live Browser Sessions

Affected Environment
macOS endpoints, particularly systems using Chromium-based browsers, Apple Keychain, Safari, Telegram, cryptocurrency wallet extensions, and devices with excessive Full Disk Access privileges.

Threat Overview
AmnesiaStealer is a Rust-based macOS infostealer distributed through ClickFix-style social engineering, designed to steal credentials, browser data, keychain material, cloud and crypto assets, and hijack authenticated browser sessions.

Exposure Timeline
First documented by Jamf Threat Labs in August 2026, with associated campaign infrastructure, malware hashes, persistence artefacts, and delivery indicators subsequently published.

Attack Surface
Spoofed GitHub download pages, user-executed Terminal commands, Chromium browser profiles, Apple Keychain data, Full Disk Access permissions, and macOS LaunchDaemon persistence mechanisms.


Technical Root Cause
The campaign relies primarily on social engineering rather than a software vulnerability, tricking users into executing an encoded shell command and supplying their macOS password. Legacy TCC bypass attempts linked to CVE-2020-9771 are also present.


Exploitation Pathway
Victims paste a malicious Terminal command from a fake GitHub page, which downloads a staged payload, removes quarantine controls, executes the infostealer, captures credentials, steals sensitive data, and can deploy a remote browser-control module.

Operational Impact
Successful infection enables credential theft, keychain and browser-data compromise, cryptocurrency wallet theft, persistent access, and live hijacking of authenticated browser sessions across services such as email, banking, cloud storage, and SSO-enabled SaaS.

Strategic Impact
Compromised macOS users may provide attackers with trusted, authenticated access that preserves the victim’s IP address, device identity, and browser fingerprint, making account takeover significantly harder to detect using conventional anomaly-based controls.

Required Mitigation
Enforce current macOS patch levels, restrict or monitor unsigned and ad-hoc-signed Mach-O execution from /tmp, apply least-privilege Full Disk Access, and train users never to paste untrusted Terminal commands from websites.

Incident Response Guidance
Hunt for /tmp/.com.apple.dt.<digits>, ~/.pwd, and /Library/LaunchDaemons/com.apple.ReportCrash.agent_<digits>.plist; review connections to published campaign domains, isolate affected hosts, and rotate potentially exposed credentials and browser sessions.

References
Jamf Threat Labs
SecurityWeek
BleepingComputer
GBHackers
SC Media
CybersecurityNews
MacTech

Download the Full Report

Explore More of the Latest Threat Intelligence

Trusted by clients worldwide

Logo
Logo
Logo
Logo
Logo
Logo

Your 24/7 Security Partner

Led by human expertise and powered by the VisionX platform, we provide you with a 24/7 unbeatable Managed Detection & Response capability giving you transparent and consolidated security solutions.

Awards Image
Awards Image
Awards Image
Awards Image
Awards Image
Awards Image