A new macOS infostealer dubbed AmnesiaStealer was discovered using the ClickFix social-engineering technique for initial access and includes a second stage that grants live control of Chromium browsers, Jamf reported Thursday.The Rust-based stealer is installed through a fake GitHub “Download for macOS” page that instructs the victim to copy and paste a base64-encoded command to their Terminal. This command retrieves a dropper script that downloads a password-protected ZIP archive and then extracts and executes the AmnesiaStealer payload from the archive.After performing basic reconnaissance, the malware uses AppKit NSAlert to display a password prompt stating “Installer wants to make changes.” Once the password is received and validated, the stealer goes after the user’s Keychain, Apple Notes and files.Prior to beginning its stealing routine, the malware mutes the system sound to prevent the user from hearing the sound played when files are duplicated in Finder. While AmnesiaStealer mainly uses cat and cp commands to collect stolen files, duplicate is used for Safari cookies, Notes attachments, Safari Form Values, ~/Library/Keychains/<hardware UUID> (which contains Keychain-related cryptographic material) and any Notes not obtained via cat.“Because duplicate makes Finder the process that reads each file, these steps access data the malware cannot directly reach without prompting the user. The Safari cookie step tries cat first and falls back to duplicate only when that fails,” Jamf Senior Threat and Detections Researcher Thijs Xhaflaire explained.AmnesiaStealer targets files with the extensions txt, pdf, rtf, doc, key, jpg, png, csv and wallet. It uses generic pattern matching to search for potential cryptocurrency wallet browser extensions across Local Extension Settings, Extensions and IndexedDB rather than including specific hard-coded wallet names. The infostealer also targets Telegram session data.For Chromium browser data theft, the malware targets 16 distinct browsers, including Google Chrome, Brave, Arc and Microsoft Edge. For each browser and profile, it copies the Extensions directory along with the following files: Cookies, Login Data, Login Data for Account, Web Data, History, Bookmarks, Local State and Preferences.The researchers noted that some of the malware’s capabilities are held back by updates made by Apple in later macOS versions including macOS 26 (Tahoe), with some of these restrictions noted in debugging comments made by the malware developer. For example, one of the techniques it attempts to use for Safari cookie theft when other methods fail is an APFS snapshot bypass based on an exploit for CVE-2020-9771, which was patched by Apple in macOS Catalina 10.15.4 and 10.15.5. The technique now only works if the Terminal or malware process already hold Full Disk Access, which the researchers note may be possible in the case of “power users and developers.”AmnesiaStealer also attempts to recover the Safe Storage password for each browser, but the malware author’s comments note “no keys recovered” on macOS 26 and above, leading to the use of a fallback method where the malware overwrites the Safe Storage password entirely with a hardcoded value, rendering any previously stored passwords and cookies undecryptable.“This sequence is a high-value detection. Browsers create Safe Storage entries through the Security framework and never through the security binary, so a process deleting and rewriting one has no benign explanation,” the researchers note.
Ransomware, Malware
MacOS AmnesiaStealer malware spread through ClickFix, grants live browser control
(Credit: Felix Geringswald – stock.adobe.com)
An In-Depth Guide to Ransomware
Get essential knowledge and practical strategies to protect your organization from ransomware attacks.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
Related Terms
AdwareYou can skip this ad in 5 seconds
