AmnesiaStealer Malware Targets macOS Users, Steals Data
TL;DR. A multi-stage Rust-based macOS information stealer, AmnesiaStealer, is being distributed through fake GitHub download pages, harvesting user credentials and browser data. - The malware bypasses Transparency, Consent, and Control (TCC) to access Safari cookies and full disk data, establishing persistence. - It clones victim browser profiles for attacker control, rendering saved Chromium-based browser passwords unrecoverable. - Jamf researchers discovered the infostealer, noting its builder-driven configuration and OS-version branched logic.
- AmnesiaStealer is a Rust-based macOS malware distributed via counterfeit GitHub pages.
- It steals passwords, keychain info, Chromium-based browser data, and Safari cookies.
- The malware includes a remote-control stage for interactive browser session control.
Sources
- AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions — securityweek.com