logo

AmnesiaStealer: a multi-stage Rust-based macOS infostealer that hijacks Chromium browsers

ID: 55894bb5-d3e6-509e-b099-4986d907b209

STIX ID: report--55894bb5-d3e6-509e-b099-4986d907b209

Feed Name: Jamf Blog

Threat Score
78/100

Date Published: 2026-08-11

Date Updated: 2026-08-13

...
...

Jamf Threat Labs analyzed AmnesiaStealer, a multi-stage Rust macOS infostealer delivered via a counterfeit GitHub "Download for macOS" lure that convinces victims to paste a Terminal command; Stage 1 harvests login passwords, unlocks and copies keychains, Apple Notes, Telegram data and Chromium profiles (including a destructive fallback that rewrites Chrome Safe Storage on macOS 26), stages and exfiltrates data to an Amnesia Panel C2, installs a LaunchDaemon for persistence, and Stage 2 is a streaming module that clones the victim's browser profile, runs it headless under operator control via the Chrome DevTools Protocol to steal and export cookies and live sessions; the report includes detailed IOCs, hashes, URLs, artifacts and observed TTPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.