Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Jellyfin does everything Plex does — except charge you for it

    August 16, 2026

    Why do so many AI chatbots call themselves Nova? I asked ChatGPT, Claude, Gemini and more to name themselves

    August 16, 2026

    AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions

    August 16, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions
    AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions
    Cybersecurity

    AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions

    The Tech GuyBy The Tech GuyAugust 16, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    A multi-stage Rust-based macOS information stealer has been distributed through a counterfeit GitHub download page in recent ClickFix attacks, Jamf reports.

    Advertisement

    The fake download page lures victims into pasting a command into Terminal, which leads to the newly discovered AmnesiaStealer being installed.

    As part of a three-stage infection chain, a shell script runs to fetch and execute the payload, the infostealer harvests data, and a third module is run on command to provide interactive control over the victims’ browsers.

    “Its objectives overlap with families such as Atomic (AMOS), MacSync and CrashStealer. Three traits set it apart: a builder-driven configuration, OS version-branched logic that reaches for patched macOS bypasses, and the remote-control second stage,” Jamf notes.

    After execution, the malware performs reconnaissance, prompts the user to provide their login password and validates it locally, copies login and data-protection keychains, and harvests Chromium-based browser databases, Apple Notes, and documents.

    AmnesiaStealer also attempts two Transparency, Consent, and Control (TCC) framework bypasses to gain Safari cookie and full disk access, archives the harvested data and sends it to the command-and-control (C&C) server, and installs a LaunchDaemon for persistence.

    Advertisement. Scroll to continue reading.

    If it receives a remote_stream command, the malware downloads and runs a stream module that clones the victim’s browser profile and launches it headless to provide the attackers with full control over the browser session.

    The information stealer targets six Chromium-based browsers, including Chrome, Brave, Arc, and Edge, and was seen overwriting the per-browser Safe Storage key in the login keychain with an attacker-controlled value, rendering previously saved passwords and cookies unrecoverable.

    “The malware accepts that loss: unable to recover the existing key on macOS 26, it swaps the victim’s saved data for a key the operator already knows, so anything encrypted afterward can be decrypted operator-side,” Jamf notes.

    To steal Safari cookies and access the TCC database, the malware uses an old TCC bypass (CVE-2020-9771). On macOS 26, the attack works only if the Terminal or the malware process already has Full Disk Access.

    The final stream module, which is executed on demand, is an interactive remote-control component that uses the Chrome DevTools Protocol (CDP) to launch a headless copy of the browser, creating a relay channel through which the attacker can control the victim’s browser session.

    “The operator receives a live screencast of the session at around 3fps and can drive it with a full input set: keyboard, mouse, scroll, navigation, and tab management. These are translated into CDP calls against the headless browser in real time. This is a hands-on-keyboard hidden browser session, not an automated dump,” Jamf notes.

    Related: Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset

    Related: Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities

    Related: Mozilla Issues New Firefox GPG Key Following Exposure

    Related: ‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Hackers Exploiting Unpatched GeoServer Zero-Day

    August 16, 2026

    14,000 Trezor Customers Impacted by Data Breach at ShipMonk

    August 15, 2026

    Over 1,000 Charities Hit by Beacon CRM Data Breach

    August 15, 2026

    1.6 Million Likely Impacted by RingCentral Data Breach

    August 15, 2026

    Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal

    August 15, 2026

    Trivy, Not LiteLLM Behind the 2,500 Org Compromise

    August 14, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026391 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026210 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Jellyfin does everything Plex does — except charge you for it

    August 16, 2026

    Why do so many AI chatbots call themselves Nova? I asked ChatGPT, Claude, Gemini and more to name themselves

    August 16, 2026

    AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions

    August 16, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.