Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions

0
High
Published: 08/14/2026 (08/14/2026, 06:41:43 UTC)
Source: SecurityWeek

Description

AmnesiaStealer is a Rust-based macOS malware that steals sensitive user data including passwords, keychain items, browser data from Chromium-based browsers, and Safari cookies. It is distributed via a fake GitHub download page that tricks users into running a command in Terminal. The malware operates in three stages: initial infection, data harvesting, and a remote-control module that allows attackers to control browser sessions interactively. It uses known macOS bypasses to access protected data and installs persistence mechanisms. The malware overwrites browser encryption keys to decrypt future data and uses an old TCC bypass for Safari cookie theft. The remote-control component uses the Chrome DevTools Protocol to provide attackers with live control over victim browsers.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 06:56:23 UTC

Technical Analysis

AmnesiaStealer is a multi-stage Rust-based macOS information stealer distributed through a counterfeit GitHub download page. The infection chain involves a shell script fetching and executing the payload, which harvests passwords, keychain data, Chromium-based browser databases, Apple Notes, and documents. It attempts two TCC framework bypasses to gain Safari cookie and full disk access, including exploiting CVE-2020-9771. The malware overwrites the Safe Storage key in the login keychain for targeted Chromium browsers, allowing attackers to decrypt future saved passwords and cookies. It installs a LaunchDaemon for persistence. On command, it downloads a stream module that launches a headless browser controlled remotely via the Chrome DevTools Protocol, enabling attackers to interactively control the victim's browser session with live screencasting and full input control.

Potential Impact

The malware compromises user credentials, keychain data, browser cookies, and documents, potentially exposing sensitive personal and corporate information. By overwriting encryption keys, it renders previously saved browser passwords and cookies unrecoverable by the user but decryptable by the attacker. The remote-control module allows attackers to interactively control browser sessions, increasing the risk of further compromise or data theft. The use of TCC bypasses and persistence mechanisms increases the stealth and longevity of the infection. This poses a significant privacy and security risk to affected macOS users.

Defensive Guidance

No official patch or remediation is indicated for this malware. Mitigation focuses on user education to avoid executing commands from untrusted sources, especially in Terminal. Organizations should monitor for suspicious LaunchDaemon installations and unusual network traffic to command-and-control servers. Applying the latest macOS security updates may help mitigate some bypass techniques, but the malware uses known bypasses that may still be effective. Endpoint protection solutions with macOS malware detection capabilities should be employed. Users should avoid downloading software from unverified sources such as counterfeit GitHub pages.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.85,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/amnesiastealer-macos-malware-steals-data-controls-browser-sessions/","fetched":true,"fetchedAt":"2026-08-14T06:56:14.827Z","wordCount":1130}

Threat ID: 6a7ebc0ebf8831d539978b92

Added to database: 08/14/2026, 06:56:14 UTC

Last enriched: 08/14/2026, 06:56:23 UTC

Last updated: 08/14/2026, 06:56:23 UTC

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses