Close Menu
NCIJ Network NCIJ Network
    What's Hot

    On Sept 12th, ‘everyone was compassionate’: The world needs ‘to be together again’ – Richard Roeill – Spotlight

    September 13, 2026

    Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider

    September 13, 2026

    ESMA Flags Crypto Spillover, Prediction Market Risks

    September 13, 2026
    Facebook X (Twitter) Instagram
    Trending
    • On Sept 12th, ‘everyone was compassionate’: The world needs ‘to be together again’ – Richard Roeill – Spotlight
    • Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider
    • ESMA Flags Crypto Spillover, Prediction Market Risks
    • Think of the parable of a frog in boiling water. That’s us dithering as the ‘unprecedented‘ weather becomes more extreme | Helen Pilcher
    • Tesco alerts police as supermarket becomes latest victim of scam ‘endorsement’ ads | Scams
    • Matt Mullenweg tells (trolls?) Automattic staff, saying he’s back in control after CEO ouster
    • GTA Mod Adds Flock Cameras—And Lets Players Destroy Them
    • 1,400 Yemenis flee to Djibouti within 24 hours | Refugees News
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Sunday, September 13
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 15, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A multi-stage Rust-based macOS information stealer has been distributed through a counterfeit GitHub download page in recent ClickFix attacks, Jamf reports.

    The fake download page lures victims into pasting a command into Terminal, which leads to the newly discovered AmnesiaStealer being installed.

    As part of a three-stage infection chain, a shell script runs to fetch and execute the payload, the infostealer harvests data, and a third module is run on command to provide interactive control over the victims’ browsers.

    “Its objectives overlap with families such as Atomic (AMOS), MacSync and CrashStealer. Three traits set it apart: a builder-driven configuration, OS version-branched logic that reaches for patched macOS bypasses, and the remote-control second stage,” Jamf notes.

    After execution, the malware performs reconnaissance, prompts the user to provide their login password and validates it locally, copies login and data-protection keychains, and harvests Chromium-based browser databases, Apple Notes, and documents.

    AmnesiaStealer also attempts two Transparency, Consent, and Control (TCC) framework bypasses to gain Safari cookie and full disk access, archives the harvested data and sends it to the command-and-control (C&C) server, and installs a LaunchDaemon for persistence.

    Advertisement. Scroll to continue reading.

    If it receives a remote_stream command, the malware downloads and runs a stream module that clones the victim’s browser profile and launches it headless to provide the attackers with full control over the browser session.

    The information stealer targets six Chromium-based browsers, including Chrome, Brave, Arc, and Edge, and was seen overwriting the per-browser Safe Storage key in the login keychain with an attacker-controlled value, rendering previously saved passwords and cookies unrecoverable.

    “The malware accepts that loss: unable to recover the existing key on macOS 26, it swaps the victim’s saved data for a key the operator already knows, so anything encrypted afterward can be decrypted operator-side,” Jamf notes.

    To steal Safari cookies and access the TCC database, the malware uses an old TCC bypass (CVE-2020-9771). On macOS 26, the attack works only if the Terminal or the malware process already has Full Disk Access.

    The final stream module, which is executed on demand, is an interactive remote-control component that uses the Chrome DevTools Protocol (CDP) to launch a headless copy of the browser, creating a relay channel through which the attacker can control the victim’s browser session.

    “The operator receives a live screencast of the session at around 3fps and can drive it with a full input set: keyboard, mouse, scroll, navigation, and tab management. These are translated into CDP calls against the headless browser in real time. This is a hands-on-keyboard hidden browser session, not an automated dump,” Jamf notes.

    Related: Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset

    Related: Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities

    Related: Mozilla Issues New Firefox GPG Key Following Exposure

    Related: ‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad

    AmnesiaStealer browser controls data macOS Malware Sessions Steals
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider

    Microsoft Excel KB5002914 update breaks copy and paste for some users

    Surfshark VPN says hackers breached internal testing, proxy servers

    Conti ransomware gang member sentenced to 4 years in prison

    GitLab urges users to patch max severity path traversal flaw

    Fly Language Model (FLM) Wires the Full Fruit Fly Connectome Into a Frozen 1.2B LLM, and Its Own Controls Show the Wiring Does Not Help

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    On Sept 12th, ‘everyone was compassionate’: The world needs ‘to be together again’ – Richard Roeill – Spotlight

    September 13, 2026

    Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider

    September 13, 2026

    ESMA Flags Crypto Spillover, Prediction Market Risks

    September 13, 2026

    Think of the parable of a frog in boiling water. That’s us dithering as the ‘unprecedented‘ weather becomes more extreme | Helen Pilcher

    September 13, 2026
    Latest Posts

    Washington’s Badger Mountain Solar Project Canceled by Developer — ProPublica

    August 3, 2026

    Rejected Wisconsin data center proposal had guaranteed tax revenue, housing

    August 3, 2026

    EIG’s MidOcean Energy lines up new investment as NYK spreads its LNG wings

    August 3, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    On Sept 12th, ‘everyone was compassionate’: The world needs ‘to be together again’ – Richard Roeill – Spotlight

    September 13, 2026

    Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider

    September 13, 2026

    ESMA Flags Crypto Spillover, Prediction Market Risks

    September 13, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.