Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AmnesiaStealer Malware Targets macOS Through Fake Sites

AmnesiaStealer Malware Targets macOS Through Fake Sites

Posted on August 13, 2026 By CWS

A newly detected macOS malware named AmnesiaStealer is making rounds, exploiting a fraudulent GitHub download page to deceive Mac users. The attackers lure victims into executing a malicious Terminal command that installs the malware discreetly, potentially allowing attackers to take over the victim’s browser sessions without detection.

Deceptive GitHub Page

Researchers from Jamf Threat Labs identified this threat, discovering a fake website at github.aoitour[.]com, which closely mimics GitHub’s appearance, complete with the dark theme and logos. The site falsely claims to offer a ‘Terminal installation’ guide, encouraging users to execute a command in their Terminal, thereby granting malware access to their systems.

This social engineering tactic, known as ClickFix, has been previously employed to distribute other malware strains like Atomic (AMOS) and MacSync. It demonstrates the reuse of deceptive methods by cybercriminals across different campaigns.

Malware Execution and Capabilities

Upon execution of the command, a concealed shell script downloads and extracts a disguised binary, launching the payload while erasing traces of its activities. The malware, leveraging a Rust-based infostealer, profiles the system and captures login credentials by mimicking an installation prompt.

It accesses sensitive information, including keychain details, browser data, and social media sessions. The attack’s sophistication is evident in its ability to clone browser profiles in headless mode, granting attackers live access to the victim’s online activities.

Preventive Measures and Security Recommendations

Despite attempts to evade Apple’s privacy controls, many of the malware’s techniques are outdated on newer macOS versions. Nevertheless, the core functionality of credential and session hijacking remains effective, particularly against users with broad system permissions.

To safeguard against such threats, users are advised never to execute unfamiliar Terminal commands, especially from unverified download sources. Regularly updating macOS, enabling comprehensive threat protection, and exercising caution with any software installation prompts are critical defense strategies.

The ongoing evolution of AmnesiaStealer highlights the importance of vigilance and proactive security measures in protecting macOS users from increasingly sophisticated cyber threats.

Cyber Security News Tags:AmnesiaStealer, browser session hijack, credential theft, Cybersecurity, GitHub phishing, InfoStealer, Jamf Threat Labs, macOS malware, Rust-based malware, terminal command

Post navigation

Previous Post: Beacon CRM Data Breach: Full Database Stolen After AWS Key Leak

Related Posts

ValleyRAT_S2 Attacking Organizations to Deploy Stealthy Malware and Extract Financial Details ValleyRAT_S2 Attacking Organizations to Deploy Stealthy Malware and Extract Financial Details Cyber Security News
Boggy Serpens Intensifies Cyberattacks on Global Targets Boggy Serpens Intensifies Cyberattacks on Global Targets Cyber Security News
Fortinet SSO Vulnerability Actively Exploited to Hack Firewalls and Gain Admin Access Fortinet SSO Vulnerability Actively Exploited to Hack Firewalls and Gain Admin Access Cyber Security News
Threat Actors Allegedly Listed iOS 26 Full‑Chain 0‑Day Exploit on Dark Web Threat Actors Allegedly Listed iOS 26 Full‑Chain 0‑Day Exploit on Dark Web Cyber Security News
DarkCloud Stealer Employs New Infection Chain and ConfuserEx-Based Obfuscation DarkCloud Stealer Employs New Infection Chain and ConfuserEx-Based Obfuscation Cyber Security News
INE Expands Cross-Skilling Innovations INE Expands Cross-Skilling Innovations Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AmnesiaStealer Malware Targets macOS Through Fake Sites
  • Beacon CRM Data Breach: Full Database Stolen After AWS Key Leak
  • Fortinet Addresses Critical Security Flaws in Key Products
  • Armored Likho Tool Compromises Telegram & Records Conversations
  • Jewelbug Exploits Browsers to Infiltrate Government Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AmnesiaStealer Malware Targets macOS Through Fake Sites
  • Beacon CRM Data Breach: Full Database Stolen After AWS Key Leak
  • Fortinet Addresses Critical Security Flaws in Key Products
  • Armored Likho Tool Compromises Telegram & Records Conversations
  • Jewelbug Exploits Browsers to Infiltrate Government Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark