AmnesiaStealer is a multi-stage Rust-based macOS infostealer distributed through ClickFix social-engineering campaigns that use counterfeit GitHub-themed download pages to trick users into pasting a malicious command into Terminal. The infection chain uses an initial shell-based loader to retrieve and execute the payload, followed by a primary stealer stage and an on-demand browser streaming module. The malware is named after the Amnesia Panel backend associated with its operations.
The primary stealer stage performs host reconnaissance and steals a broad range of data from macOS systems. It captures the victim’s macOS password through a fake native installer-style prompt, validates the credential locally, and reuses it to unlock protected data sources such as Keychain material. It harvests data from multiple Chromium-based browsers, including cookies, saved logins, browsing history, bookmarks, preferences, local state, extension data, and other profile artifacts. It also targets Safari cookies, Apple Notes, Telegram session data, selected user documents, and cryptocurrency wallet-related browser artifacts. Some builds include clipboard hijacking logic aimed at cryptocurrency theft. Collected data is staged, archived, and exfiltrated to attacker-controlled infrastructure.
A notable capability is its secondary streaming module, which can be fetched on command to clone a victim’s Chromium profile, launch a hidden headless browser, and provide operators with live interactive control over authenticated browser sessions through the Chrome DevTools Protocol. This enables covert navigation, keyboard and mouse interaction, tab management, screencasting, and plaintext cookie extraction from the live browser context, effectively supporting session hijacking without disrupting the visible user session. The module also includes anti-detection measures intended to reduce browser automation fingerprinting.
AmnesiaStealer includes macOS-specific tradecraft such as attempts to access protected files through Finder-mediated operations, muting system audio to reduce user awareness, and establishing persistence via a LaunchDaemon masquerading as an Apple crash-reporting component. It also contains OS-version-aware logic and attempts older macOS privacy-bypass techniques, including methods related to CVE-2020-9771, although these are not consistently effective on newer macOS releases. On newer macOS versions, the malware has been observed using a destructive fallback that rewrites Chromium Safe Storage key material with an attacker-known value, enabling later decryption of newly protected browser secrets while breaking the victim’s access to previously stored browser data.
AmnesiaStealer has been linked by tradecraft overlap to campaigns involving other macOS stealers such as Atomic Stealer and MacSync, and the operator environment has shown Russian-language characteristics. It primarily targets macOS users and is especially dangerous for theft of credentials, browser secrets, cryptocurrency-related data, and active authenticated web sessions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Steal cookies from Safari based on the macOS version, using a TCC bypass flaw (CVE-2020-9771) to target macOS machines running Catalina. | Cybersecurity researchers have disclosed details of a new macOS-oriented, Rust-based information stealer called AmnesiaStealer that's capable of hijacking Chromium web browsers to steal session data.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Establish persistence by means of a root LaunchDaemon that impersonates Apple's crash reporting service.
with the attacker able to interact in real time via full keyboard and mouse inputs. | After performing basic reconnaissance, the malware uses AppKit NSAlert to display a password prompt stating “Installer wants to make changes.” Once the password is received and validated, the stealer goes after the user’s Keychain, Apple Notes and files.
The malware captures the victim’s macOS password and uses it to collect keychain data...
AmnesiaStealer that's capable of hijacking Chromium web browsers to steal session data.
The second is a Rust infostealer that harvests the Keychain, browsers, Apple Notes, and Telegram.
Also present is an AppleScript file that mutes the system sound and then proceeds to harvest data from Apple Notes, Telegram sessions, Safari, files matching certain extensions (.txt, .pdf, .rtf, .doc, .wallet, .key, .jpg, .png, and .csv) across ~/Desktop, ~/Documents, and ~/Download folders
with the attacker able to interact in real time via full keyboard and mouse inputs. | After performing basic reconnaissance, the malware uses AppKit NSAlert to display a password prompt stating “Installer wants to make changes.” Once the password is received and validated, the stealer goes after the user’s Keychain, Apple Notes and files.
The malware captures the victim’s macOS password and uses it to collect keychain data...
Two WebSockets form a relay channel to send operator commands to the browser and a 3 FPS screencast back to the attacker
Enable or disable a clipboard-hijacking (aka clipper) module ("CLIPPER_ENABLED") capable of targeting cryptocurrencies like Bitcoin, Bitcoin Cash, Ethereum, TRON, Litecoin, Monero, Solana, Ripple, and Cosmos (ATOM).
This allows the hacker to access victims' authenticated sessions while preserving the identifiers associated with the browser, host, and network.
The infostealer also targets Telegram session data. For Chromium browser data theft, the malware targets 16 distinct browsers... For each browser and profile, it copies the Extensions directory along with the following files: Cookies, Login Data, Login Data for Account, Web Data, History, Bookmarks, Local State and Preferences.
The malware then establishes a WebSocket channel that connects to the operator's relay and sends a JSON registration message...
It includes the following details - Command-and-control (C2) endpoints (i.e., "debug.allllowef[.]space/send/") | It also spawns a relay channel using WebSocket to accept operator commands and report the status back to the same endpoint.
49 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
macOS infostealer distributed via ClickFix campaigns that steals browser data, passwords, cryptocurrency wallet data, Apple Notes, documents, Telegram sessions, system information, and keychain data. It also includes a stream_module that clones Chromium profiles into a hidden headless browser and gives the operator live remote control over authenticated browser sessions via the Chrome DevTools Protocol.
A Rust-based macOS infostealer delivered via a fake GitHub download page and terminal-executed base64 command. It steals Keychain material, Apple Notes, files, Telegram session data, and Chromium/Safari browser data, targets cryptocurrency wallet-related browser extension data, and includes a second-stage module that enables live remote control of Chromium browsers through the Chrome DevTools Protocol and cookie theft.
A stealer targeting macOS users that includes a stream_module enabling hidden interactive control over a Chromium browser via CDP and exporting cookies in plaintext.
A macOS-focused Rust infostealer distributed via ClickFix social engineering. It steals credentials, browser data, live sessions, Apple Notes and Telegram data, validates prompted passwords locally to unlock keychain-protected records, stages and exfiltrates collected data, and deploys a second-stage module that covertly takes remote control of cloned Chromium-family browser profiles and steals cookies via the DevTools protocol.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.