Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AmnesiaStealer Malware Targets macOS Users

AmnesiaStealer Malware Targets macOS Users

Posted on August 14, 2026 By CWS

A sophisticated Rust-based malware known as AmnesiaStealer has emerged, aiming at macOS users through deceptive GitHub download pages, according to security firm Jamf. This recent cyber threat has been associated with ClickFix campaigns, utilizing a multi-stage attack strategy to infiltrate systems.

Infiltration Through Fake GitHub Links

The malware campaign begins by enticing users into executing a command in the Terminal. This action triggers the installation of AmnesiaStealer on the victim’s device. The infiltration process involves a three-stage infection chain, where a shell script is used to download and execute the malicious payload.

Once installed, the malware embarks on a data-harvesting mission, gathering sensitive information from the infected macOS devices. The final stage of the attack involves an interactive module that grants attackers control over the victim’s browser sessions.

Unique Traits and Functionality

AmnesiaStealer is distinguished by its builder-driven configuration and the ability to adapt its operations based on the macOS version. It also employs a second-stage remote control feature, setting it apart from other malware families such as Atomic (AMOS), MacSync, and CrashStealer.

After deployment, the malware conducts reconnaissance, prompting users for their login passwords which it validates locally. It then proceeds to duplicate login credentials and data-protection keychains, while extracting data from Chromium-based browsers, Apple Notes, and documents.

Advanced Data Theft Techniques

This malware seeks to bypass macOS security frameworks to access Safari cookies and full disk data. It leverages an outdated TCC bypass (CVE-2020-9771), particularly effective on systems where Terminal or the malware process possesses Full Disk Access.

In cases where a remote_stream command is received, AmnesiaStealer downloads a module to clone and control the browser profile. The malware targets browsers such as Chrome, Brave, Arc, and Edge, manipulating stored Safe Storage keys to make previously saved passwords inaccessible.

The malware’s advanced capabilities include executing a stream module upon request, which uses the Chrome DevTools Protocol (CDP) to operate a headless browser. This feature allows attackers to remotely manipulate the victim’s browsing session in real-time.

Cybersecurity experts emphasize the importance of vigilance against such threats, as AmnesiaStealer represents a significant risk to macOS users due to its sophisticated techniques and ability to compromise browser and data security.

Security Week News Tags:AmnesiaStealer, browser security, Cybersecurity, data theft, GitHub phishing, information stealer, macOS, Malware, remote control malware, TCC bypass

Post navigation

Previous Post: New DRAM Attack Threatens CPU Security Measures
Next Post: Hackers Target GeoServer’s Unpatched Vulnerability

Related Posts

Iranian Cyber Attackers Deploy Versatile C&C System Iranian Cyber Attackers Deploy Versatile C&C System Security Week News
Join the Supply Chain & Risk Summit for Key Insights Join the Supply Chain & Risk Summit for Key Insights Security Week News
Hackers Stole 300,000 Crash Reports From Texas Department of Transportation Hackers Stole 300,000 Crash Reports From Texas Department of Transportation Security Week News
Helmet Security Emerges From Stealth Mode With  Million in Funding Helmet Security Emerges From Stealth Mode With $9 Million in Funding Security Week News
Google Paid Out 8,000 at Live Hacking Event Google Paid Out $458,000 at Live Hacking Event Security Week News
Langflow Vulnerability Exploited Rapidly After Disclosure Langflow Vulnerability Exploited Rapidly After Disclosure Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Ethereum Used for Covert Malware Communication
  • Pentagon Data Breach Affects Over 3 Million Individuals
  • Kiteworks Resolves Critical Security Issue in Nine-Hour Downtime
  • Botnet Exploits AI Credits and Data Theft Risks
  • RemoteThreat Secures $7M for Cyber Operations Platform

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Ethereum Used for Covert Malware Communication
  • Pentagon Data Breach Affects Over 3 Million Individuals
  • Kiteworks Resolves Critical Security Issue in Nine-Hour Downtime
  • Botnet Exploits AI Credits and Data Theft Risks
  • RemoteThreat Secures $7M for Cyber Operations Platform

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark