< Back to all clusters
[TECHNOLOGY] · 7 sources

started · updated

Jamf Threat Labs identifies AmnesiaStealer macOS malware

Jamf Threat Labs has identified a new multi-stage macOS infostealer named ‘AmnesiaStealer’. The malware is distributed via counterfeit GitHub pages that trick users into downloading a payload through a fake ‘Download for macOS’ button.

Written in Rust, the malware operates in multiple stages. The initial payload harvests sensitive data including the macOS keychain, Apple Notes, Telegram data, and browser credentials. It also attempts to use various macOS bypasses, some of which have already been patched by Apple.

A distinctive feature of AmnesiaStealer is its second stage, a remote control module that provides attackers with hidden, interactive control over the victim’s Chromium browser. This allows for the theft of live authenticated sessions and cookies via the DevTools Protocol. The malware also employs stealth scripts to patch browser fingerprinting APIs, helping it evade detection by the websites it visits.

Entities

AmnesiaStealer · GitHub · Jamf Threat Labs