AmnesiaStealer macOS Malware: Data Theft & Browser Session Control

www.news4hackers.com-amnesiastealer-macos-malware-data-theft-browser-session-control-amnesiastealer-macos-malware-data-theft-browser-session-control

A multi-stage Rust-based macOS information stealer has been distributed via a counterfeit GitHub repository.

Overview of AmnesiaStealer

A multi-stage Rust-based macOS information stealer has been distributed via a counterfeit GitHub repository. The malicious payload operates through a three-stage infection process. The initial stage involves a shell script that downloads and executes the primary payload. The second stage focuses on data collection, while the third module enables remote interaction with the victim’s web browsers. The malware’s functionality overlaps with known threats such as Atomic (AMOS), MacSync, and CrashStealer. However, it distinguishes itself through three key features: a configuration generated by a builder tool, operating system version-specific logic designed to bypass patched macOS protections, and a remote-control second stage.

Infection Process

Upon execution, the malware conducts system reconnaissance, prompts users for their login password, and verifies it locally. It then copies login and data-protection keychains and extracts Chromium-based browser databases, Apple Notes, and documents. AmnesiaStealer attempts two Transparency, Consent, and Control (TCC) framework bypasses to access Safari cookies and gain full disk access. It archives the stolen data and transmits it to a command-and-control (C&C) server. A LaunchDaemon is installed to ensure persistence.

Data Collection and Theft

If the malware receives a remote_stream command, it activates an interactive remote-control component. This module leverages the Chrome DevTools Protocol (CDP) to launch a headless browser instance, creating a relay channel for attacker control. The operator receives a low-frame-rate (approximately 3fps) live screencast of the victim’s session and can manipulate the browser through real-time input, including keyboard, mouse, scroll, navigation, and tab management. This interactive session is not an automated data dump but a direct, hands-on control mechanism.

Targeted Browsers and Keychain Manipulation

The malware specifically targets six Chromium-based browsers, including Chrome, Brave, Arc, and Edge. It overwrites the per-browser Safe Storage key in the login keychain with an attacker-controlled value, rendering previously stored passwords and cookies irrecoverable. The malware acknowledges this data loss, as it cannot retrieve the original key on macOS 26. Instead, it replaces the victim’s saved data with a key known to the attacker, enabling decryption of newly encrypted information.

TCC Bypass and Persistence

To steal Safari cookies and access the TCC database, AmnesiaStealer employs an outdated TCC bypass (CVE-2020-9771). On macOS 26, this exploit requires either Terminal or the malware process to already have Full Disk Access. The final stream module, activated on demand, provides the interactive remote-control functionality described earlier.

Technical Analysis and Implications

Technical analysis by Jamf highlights the malware’s sophisticated evasion techniques and its ability to maintain persistent access while evading detection. The attack chain underscores the evolving tactics of threat actors targeting macOS systems through supply chain compromises and custom-built tools.



About Author

en_USEnglish