Skip to main content
Aggregate CSO Online 网络安全 17 Aug 2026 - 20:01

New macOS malware turns stolen browsers into attacker-controlled sessions

RSS 官方收录 · 可信分层展示

关键摘要

Mac users are being freshly warned of suspicious websites asking them to open Terminal and install software.…

  • Jamf Threat Labs has uncovered a multi-stage macOS infostealer, dubbed…
  • The campaign is designed to steal credentials and sensitive data befor…
  • The attack was found mimicking GitHub’s dark theme, Octocat branding a…

摘要引擎:抽取

正文提要

Mac users are being freshly warned of suspicious websites asking them to open Terminal and install software. Jamf Threat Labs has uncovered a multi-stage macOS infostealer, dubbed AmnesiaStealer, that uses a ClickFix-style fake GitHub download page to trick victims into executing a command that installs malware.

The campaign is designed to steal credentials and sensitive data before escalating into silent, interactive control of the victim’s Chromium browser, Jamf researchers said in a blog post.

The attack was found mimicking GitHub’s dark theme, Octocat branding and a “Verified Publisher” badge. Instead of providing an application, as promised in the lure, the page tells users to open Terminal, paste a command and enter their Mac password.

According to Jamf, the same fake download template has been used to distribute other macOS stealers including Atomic (AMOS) and MacSync.

The Rust-based Amnesia, however, adds a dedicated module for providing attackers with covert browser control. A “working collector paired with a working browser-hijack stage” makes the threat worth tracking, the researchers pointed out.

It all starts with a fake GitHub download

The social-engineering component involves a “Download for macOS” workflow within a fake site that tricks in a Terminal command instead of the promised application. That command retrieves a shell script from the attacker infrastructure, which then downloads a password-protected ZIP containing the main malware.

The loader takes a number of steps to make the payload harder to notice, Jamf said. It extracts the binary into “/tmp,” gives it a hidden Apple-looking filename, removes the macOS quarantine attribute, applies an ad-hoc code signature and launches it silently before deleting the executable.

Password-protecting the ZIP is likely an attempt to complicate automated inspection, the researchers noted.

The Rust-based universal Mach-O finally deployed was analyzed to be built for both Intel and Apple silicon Macs. Jamf said that it can collect the macOS login password through a native-looking prompt, as well as target the Keychain, browser data, Apple Notes, Telegram session information and files.

Additionally, the malware contains logic for attempting older macOS security bypasses, although Jamf observed most of them failing as Apple has already patched the underlying weaknesses.

Browser becoming the second target

The unusual part of AmnesiaStealer arrives through its third stage. When instructed by the command-and-control (C2) infrastructure, the malware downloads a separate Rust-based “stream_module” that launches a cloned browser profile and establishes a WebSocket connection with the attacker.

The module turns the victim’s browser into a remotely operated session. Supported commands in this mode include opening and closing tabs, navigating, scrolling, keyboard and mouse interaction and exporting cookies.

Browser cookies could be exported in plaintext through the DevTools Protocols.

Jamf pointed out that stealing an already-authenticated browser session can allow an attacker to operate with the victim’s existing access. A compromised Mac therefore becomes a remotely controlled browser endpoint, apart from leaking credentials and documents.

The researchers recommended that organizations block the indicators associated with the campaign and monitor for suspicious activity matching AmnesiaStealer’s behavior. The blog post includes IOCs covering the malware’s infrastructure, files and hashes, including the domains used to deliver the payload.

Educating enterprise users about ClickFix-style attacks, particularly fake websites that instruct them to paste commands into Terminal, and ensuring macOS endpoints are kept up to date was also advised.

打开官方原文 站点原文页 可信分区 本信源更多 今日简报 分享图 RSS 稍后再看列表