Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AmnesiaStealer Malware Targets macOS Users

AmnesiaStealer Malware Targets macOS Users

Posted on August 14, 2026 By CWS

A sophisticated Rust-based malware known as AmnesiaStealer has emerged, aiming at macOS users through deceptive GitHub download pages, according to security firm Jamf. This recent cyber threat has been associated with ClickFix campaigns, utilizing a multi-stage attack strategy to infiltrate systems.

Infiltration Through Fake GitHub Links

The malware campaign begins by enticing users into executing a command in the Terminal. This action triggers the installation of AmnesiaStealer on the victim’s device. The infiltration process involves a three-stage infection chain, where a shell script is used to download and execute the malicious payload.

Once installed, the malware embarks on a data-harvesting mission, gathering sensitive information from the infected macOS devices. The final stage of the attack involves an interactive module that grants attackers control over the victim’s browser sessions.

Unique Traits and Functionality

AmnesiaStealer is distinguished by its builder-driven configuration and the ability to adapt its operations based on the macOS version. It also employs a second-stage remote control feature, setting it apart from other malware families such as Atomic (AMOS), MacSync, and CrashStealer.

After deployment, the malware conducts reconnaissance, prompting users for their login passwords which it validates locally. It then proceeds to duplicate login credentials and data-protection keychains, while extracting data from Chromium-based browsers, Apple Notes, and documents.

Advanced Data Theft Techniques

This malware seeks to bypass macOS security frameworks to access Safari cookies and full disk data. It leverages an outdated TCC bypass (CVE-2020-9771), particularly effective on systems where Terminal or the malware process possesses Full Disk Access.

In cases where a remote_stream command is received, AmnesiaStealer downloads a module to clone and control the browser profile. The malware targets browsers such as Chrome, Brave, Arc, and Edge, manipulating stored Safe Storage keys to make previously saved passwords inaccessible.

The malware’s advanced capabilities include executing a stream module upon request, which uses the Chrome DevTools Protocol (CDP) to operate a headless browser. This feature allows attackers to remotely manipulate the victim’s browsing session in real-time.

Cybersecurity experts emphasize the importance of vigilance against such threats, as AmnesiaStealer represents a significant risk to macOS users due to its sophisticated techniques and ability to compromise browser and data security.

Security Week News Tags:AmnesiaStealer, browser security, Cybersecurity, data theft, GitHub phishing, information stealer, macOS, Malware, remote control malware, TCC bypass

Post navigation

Previous Post: New DRAM Attack Threatens CPU Security Measures
Next Post: Hackers Target GeoServer’s Unpatched Vulnerability

Related Posts

White House to Discuss AI Advancements with Anthropic CEO White House to Discuss AI Advancements with Anthropic CEO Security Week News
Critical NGINX Vulnerability PoC Code Released Critical NGINX Vulnerability PoC Code Released Security Week News
Bill Aims to Create National Strategy for Quantum Cybersecurity Migration Bill Aims to Create National Strategy for Quantum Cybersecurity Migration Security Week News
175,000 Exposed Ollama Hosts Could Enable LLM Abuse 175,000 Exposed Ollama Hosts Could Enable LLM Abuse Security Week News
Lee Enterprises Says 40,000 Hit by Ransomware-Caused Data Breach Lee Enterprises Says 40,000 Hit by Ransomware-Caused Data Breach Security Week News
QIZ Security Secures M for Cryptography Platform QIZ Security Secures $17M for Cryptography Platform Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Kiteworks Advises Server Shutdown Amid Threat Intelligence
  • ShinyHunters Target Oracle PeopleSoft in New Cyber Campaign
  • Carbonato Botnet Targets Docker Hosts with Hermes AI
  • OpenAI Agents Breach Sandbox, Create 80,000 Payloads
  • Ex-Soldier Sentenced for Hacking AT&T and Verizon

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Kiteworks Advises Server Shutdown Amid Threat Intelligence
  • ShinyHunters Target Oracle PeopleSoft in New Cyber Campaign
  • Carbonato Botnet Targets Docker Hosts with Hermes AI
  • OpenAI Agents Breach Sandbox, Create 80,000 Payloads
  • Ex-Soldier Sentenced for Hacking AT&T and Verizon

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark