Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AmnesiaStealer Malware Targets macOS Through Fake Sites

AmnesiaStealer Malware Targets macOS Through Fake Sites

Posted on August 13, 2026 By CWS

A newly detected macOS malware named AmnesiaStealer is making rounds, exploiting a fraudulent GitHub download page to deceive Mac users. The attackers lure victims into executing a malicious Terminal command that installs the malware discreetly, potentially allowing attackers to take over the victim’s browser sessions without detection.

Deceptive GitHub Page

Researchers from Jamf Threat Labs identified this threat, discovering a fake website at github.aoitour[.]com, which closely mimics GitHub’s appearance, complete with the dark theme and logos. The site falsely claims to offer a ‘Terminal installation’ guide, encouraging users to execute a command in their Terminal, thereby granting malware access to their systems.

This social engineering tactic, known as ClickFix, has been previously employed to distribute other malware strains like Atomic (AMOS) and MacSync. It demonstrates the reuse of deceptive methods by cybercriminals across different campaigns.

Malware Execution and Capabilities

Upon execution of the command, a concealed shell script downloads and extracts a disguised binary, launching the payload while erasing traces of its activities. The malware, leveraging a Rust-based infostealer, profiles the system and captures login credentials by mimicking an installation prompt.

It accesses sensitive information, including keychain details, browser data, and social media sessions. The attack’s sophistication is evident in its ability to clone browser profiles in headless mode, granting attackers live access to the victim’s online activities.

Preventive Measures and Security Recommendations

Despite attempts to evade Apple’s privacy controls, many of the malware’s techniques are outdated on newer macOS versions. Nevertheless, the core functionality of credential and session hijacking remains effective, particularly against users with broad system permissions.

To safeguard against such threats, users are advised never to execute unfamiliar Terminal commands, especially from unverified download sources. Regularly updating macOS, enabling comprehensive threat protection, and exercising caution with any software installation prompts are critical defense strategies.

The ongoing evolution of AmnesiaStealer highlights the importance of vigilance and proactive security measures in protecting macOS users from increasingly sophisticated cyber threats.

Cyber Security News Tags:AmnesiaStealer, browser session hijack, credential theft, Cybersecurity, GitHub phishing, InfoStealer, Jamf Threat Labs, macOS malware, Rust-based malware, terminal command

Post navigation

Previous Post: Beacon CRM Data Breach: Full Database Stolen After AWS Key Leak
Next Post: Apple Warns iPhone Users of Spyware Threats in 110 Countries

Related Posts

Next.js Addresses Critical Security Vulnerabilities Next.js Addresses Critical Security Vulnerabilities Cyber Security News
Aembit Expands Workload IAM to Microsoft Ecosystem, Enhancing Hybrid Security for Non-Human Identities Aembit Expands Workload IAM to Microsoft Ecosystem, Enhancing Hybrid Security for Non-Human Identities Cyber Security News
Rising Cyber Threats Challenge Defense Sector Security Rising Cyber Threats Challenge Defense Sector Security Cyber Security News
Chrome’s Privacy Risks: Fingerprinting and Header Leaks Chrome’s Privacy Risks: Fingerprinting and Header Leaks Cyber Security News
Critical Vulnerability in CrowdStrike LogScale Exposed Critical Vulnerability in CrowdStrike LogScale Exposed Cyber Security News
New HTTP/2 MadeYouReset Vulnerability Enables Large-Scale DDoS Attacks New HTTP/2 MadeYouReset Vulnerability Enables Large-Scale DDoS Attacks Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Modulate Secures $25M to Combat Deepfake Audio Threats
  • Hackers Exploit ChatGPT in New ClickFix Cyber Attacks
  • AgtaBackup RAT Exploits Fake Microsoft Store to Infiltrate PCs
  • Rig Security Secures $12M to Combat AI Identity Threats
  • BotHelper RAT Exploits Encrypted Payloads for Windows Surveillance

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Modulate Secures $25M to Combat Deepfake Audio Threats
  • Hackers Exploit ChatGPT in New ClickFix Cyber Attacks
  • AgtaBackup RAT Exploits Fake Microsoft Store to Infiltrate PCs
  • Rig Security Secures $12M to Combat AI Identity Threats
  • BotHelper RAT Exploits Encrypted Payloads for Windows Surveillance

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark