AmnesiaStealer macOS Malware Hijacks Browser Sessions via Fake GitHub Lure
Key Takeaways A new macOS infostealer, AmnesiaStealer, is actively targeting Mac users through a sophisticated fake GitHub download page. The malware leverages a social engineering technique called...
Key Takeaways
- A new macOS infostealer, AmnesiaStealer, is actively targeting Mac users through a sophisticated fake GitHub download page.
- The malware leverages a social engineering technique called “ClickFix,” prompting users to execute a malicious Terminal command.
- AmnesiaStealer steals sensitive data, including login credentials, browser sessions, and other personal information.
- Its most dangerous feature allows attackers to remotely control a victim’s live browser session, enabling access to banking, email, and social media.
- While some of the malware’s evasion tactics are outdated, its core data theft capabilities remain effective, particularly against users with broad system permissions.
New macOS Infostealer AmnesiaStealer Hijacks Browser Sessions via Elaborate GitHub Impersonation
A novel macOS information stealer, dubbed AmnesiaStealer, has been identified exploiting a highly convincing counterfeit GitHub download page to compromise Mac systems. This sophisticated malware campaign deceives users into executing a malicious Terminal command, leading to the silent installation of malware and, critically, providing attackers with real-time, covert control over the victim’s browser sessions.
Table Of Content
The Deceptive GitHub Lure
Researchers at Jamf Threat Labs uncovered this threat after observing a fraudulent website, github.aoitour[.]com, meticulously designed to mimic GitHub’s official interface. The fake site replicated GitHub’s dark theme, the iconic Octocat logo, and even displayed a “Verified Publisher” badge to enhance its legitimacy.
Instead of offering a legitimate software download, the deceptive page presented a “Terminal installation” prompt. This prompt included a one-click copy button and detailed instructions, guiding visitors to open their Terminal application, paste the provided command, press Return, and subsequently enter their device password.
This social engineering tactic, known as ClickFix, has been previously employed in distributing other macOS malware families, such as Atomic (AMOS) and MacSync. This indicates a concerning trend where cybercriminal groups are reusing successful deceptive templates across various malicious campaigns.
Infection Chain and Data Exfiltration
Upon a victim pasting and executing the malicious Terminal command, a hidden shell script is triggered. This script surreptitiously downloads a password-protected ZIP archive, extracts a disguised binary into the /tmp directory, removes Apple’s quarantine flag, and then launches the malicious payload before erasing its own traces.
The subsequent stage involves a Rust-based infostealer. This component first profiles the compromised machine, then displays a fake native “Installer” password prompt to trick the user into revealing their login credentials. These stolen credentials are then used to unlock and exfiltrate data from the macOS keychain, Apple Notes, Telegram sessions, browser data, and various documents.
The malware derives its name from the “Amnesia Panel,” its command-and-control backend, with its embedded configuration secured by the key 4mn3s1a_2o26!xK.
Live Browser Session Control: The Most Severe Threat
The most alarming capability of AmnesiaStealer resides in its third component, named stream_module. This module is retrieved only upon specific instructions from the attacker’s control panel. Once deployed, it clones the victim’s browser profile, initiates it in headless mode, and establishes a connection with the Chrome DevTools Protocol.
This sophisticated technique grants the attacker a live screencast of the victim’s browser session and complete control over mouse, keyboard, and navigation. As a result, attackers can fully operate the victim’s logged-in browser sessions, including access to email, banking, and social media accounts, all without any visible indication to the victim on their own screen, as reads the Jamf Threat Labs report.
Interestingly, some of the malware’s attempts to circumvent Apple’s privacy protections rely on techniques that Apple patched years ago, including an APFS snapshot bypass from 2020. While these older evasion methods largely fail on modern macOS versions like macOS 26, with the malware’s own debug logs recording the failures, its primary functions of credential and browser-session theft remain highly effective, particularly against advanced users who might have previously granted broader system permissions.
AmnesiaStealer exemplifies a growing trend in cyberattacks where threat actors combine highly believable phishing pages with staged, remotely triggered payloads, moving beyond reliance on a single, static malware file.
What You Should Do
- Never Paste Unknown Commands: The most critical defense is to refrain from pasting any unknown commands into the Terminal, especially those originating from unsolicited download prompts or unfamiliar websites.
- Keep macOS Updated: Ensure your macOS operating system is always running the latest version to benefit from Apple’s security patches and enhancements.
- Utilize Endpoint Protection: Deploy and maintain robust browser and endpoint threat protection solutions on all macOS devices.
- Scrutinize Password Prompts: Treat any password prompt associated with a “software installer” with extreme suspicion. Always verify the legitimacy of the installer and the source before entering credentials.
- Exercise Caution with Downloads: Only download software from official and trusted sources. Be wary of third-party sites impersonating legitimate platforms.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.