Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Can a Dam Expansion Hold Back Climate Considerations on the Colorado River?

    August 15, 2026

    It’s the SUV tyranny: where have all the normal family cars gone? | Coco Khan

    August 15, 2026

    Middle East live: Israel strikes Lebanon in deadliest attack since June

    August 15, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Can a Dam Expansion Hold Back Climate Considerations on the Colorado River?
    • It’s the SUV tyranny: where have all the normal family cars gone? | Coco Khan
    • Middle East live: Israel strikes Lebanon in deadliest attack since June
    • ‘Business critical’: why even Andy Burnham is taking his social media game seriously | Social media
    • Lamborghini’s flagship Revuelto levels up with SV trim
    • Morgan Stanley’s BlackRock Bitcoin ETF Holdings Rise 23% in Q2
    • ‘Suffocating restrictions’ shadow five years of Taliban rule in Afghanistan
    • South Florida Venue Cancels Rally With a Pro-Palestinian Congresswoman
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 15
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 15, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A multi-stage Rust-based macOS information stealer has been distributed through a counterfeit GitHub download page in recent ClickFix attacks, Jamf reports.

    The fake download page lures victims into pasting a command into Terminal, which leads to the newly discovered AmnesiaStealer being installed.

    As part of a three-stage infection chain, a shell script runs to fetch and execute the payload, the infostealer harvests data, and a third module is run on command to provide interactive control over the victims’ browsers.

    “Its objectives overlap with families such as Atomic (AMOS), MacSync and CrashStealer. Three traits set it apart: a builder-driven configuration, OS version-branched logic that reaches for patched macOS bypasses, and the remote-control second stage,” Jamf notes.

    After execution, the malware performs reconnaissance, prompts the user to provide their login password and validates it locally, copies login and data-protection keychains, and harvests Chromium-based browser databases, Apple Notes, and documents.

    AmnesiaStealer also attempts two Transparency, Consent, and Control (TCC) framework bypasses to gain Safari cookie and full disk access, archives the harvested data and sends it to the command-and-control (C&C) server, and installs a LaunchDaemon for persistence.

    Advertisement. Scroll to continue reading.

    If it receives a remote_stream command, the malware downloads and runs a stream module that clones the victim’s browser profile and launches it headless to provide the attackers with full control over the browser session.

    The information stealer targets six Chromium-based browsers, including Chrome, Brave, Arc, and Edge, and was seen overwriting the per-browser Safe Storage key in the login keychain with an attacker-controlled value, rendering previously saved passwords and cookies unrecoverable.

    “The malware accepts that loss: unable to recover the existing key on macOS 26, it swaps the victim’s saved data for a key the operator already knows, so anything encrypted afterward can be decrypted operator-side,” Jamf notes.

    To steal Safari cookies and access the TCC database, the malware uses an old TCC bypass (CVE-2020-9771). On macOS 26, the attack works only if the Terminal or the malware process already has Full Disk Access.

    The final stream module, which is executed on demand, is an interactive remote-control component that uses the Chrome DevTools Protocol (CDP) to launch a headless copy of the browser, creating a relay channel through which the attacker can control the victim’s browser session.

    “The operator receives a live screencast of the session at around 3fps and can drive it with a full input set: keyboard, mouse, scroll, navigation, and tab management. These are translated into CDP calls against the headless browser in real time. This is a hands-on-keyboard hidden browser session, not an automated dump,” Jamf notes.

    Related: Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset

    Related: Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities

    Related: Mozilla Issues New Firefox GPG Key Following Exposure

    Related: ‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad

    AmnesiaStealer browser controls data macOS Malware Sessions Steals
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Hackers Exploiting Unpatched GeoServer Zero-Day

    Critical VMware vCenter RCE flaw exploited for reverse SSH access

    RingCentral data breach exposed info of 1.6 million accounts

    14,000 Trezor Customers Impacted by Data Breach at ShipMonk

    Max severity SAP Commerce Cloud flaw now targeted in attacks

    How Anthropic plans to watermark Claude’s AI-generated text

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Can a Dam Expansion Hold Back Climate Considerations on the Colorado River?

    August 15, 2026

    It’s the SUV tyranny: where have all the normal family cars gone? | Coco Khan

    August 15, 2026

    Middle East live: Israel strikes Lebanon in deadliest attack since June

    August 15, 2026

    ‘Business critical’: why even Andy Burnham is taking his social media game seriously | Social media

    August 15, 2026
    Latest Posts

    Meta just created a moderation nightmare for its smart glasses

    July 26, 2026

    Maga’s creepy baby obsession won’t solve the fertility crisis

    July 26, 2026

    France battles fire ‘whirlwinds’ as another 55,000 evacuated

    July 26, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Can a Dam Expansion Hold Back Climate Considerations on the Colorado River?

    August 15, 2026

    It’s the SUV tyranny: where have all the normal family cars gone? | Coco Khan

    August 15, 2026

    Middle East live: Israel strikes Lebanon in deadliest attack since June

    August 15, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.