AmnesiaStealer: a multi-stage Rust-based macOS infostealer that hijacks Chromium browsers
ID: 55894bb5-d3e6-509e-b099-4986d907b209
STIX ID: report--55894bb5-d3e6-509e-b099-4986d907b209
Feed Name: Jamf Blog
Jamf Threat Labs analyzed AmnesiaStealer, a multi-stage Rust macOS infostealer delivered via a counterfeit GitHub "Download for macOS" lure that convinces victims to paste a Terminal command; Stage 1 harvests login passwords, unlocks and copies keychains, Apple Notes, Telegram data and Chromium profiles (including a destructive fallback that rewrites Chrome Safe Storage on macOS 26), stages and exfiltrates data to an Amnesia Panel C2, installs a LaunchDaemon for persistence, and Stage 2 is a streaming module that clones the victim's browser profile, runs it headless under operator control via the Chrome DevTools Protocol to steal and export cookies and live sessions; the report includes detailed IOCs, hashes, URLs, artifacts and observed TTPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
