AmnesiaStealer is a multi-stage Rust-based macOS infostealer distributed through ClickFix social engineering campaigns that use counterfeit software download pages, including fake GitHub-themed lures, to trick users into pasting and executing malicious Terminal commands. The malware relies on user-driven execution rather than exploitation of a software vulnerability. After launch, it profiles the host, steals browser data and credentials, targets macOS keychain material, Apple Notes, Telegram session data, selected documents, and wallet-related browser artifacts, then stages and exfiltrates the collected data. It also establishes persistence on compromised systems through a LaunchDaemon disguised as an Apple crash-reporting component.
A notable feature of AmnesiaStealer is its theft of the victim’s macOS login password through a native-looking installer prompt, which it validates locally and reuses to unlock protected keychain data. The malware targets numerous Chromium-family browsers, collecting cookies, login databases, history, bookmarks, preferences, extension data, and related artifacts, and attempts to recover browser Safe Storage keys from the login keychain. Some observed builds also include cryptocurrency-focused clipboard hijacking functionality.
Its most distinctive capability is an operator-controlled browser streaming module fetched on demand as a later stage. That module clones a victim’s Chromium browser profile, launches a hidden headless browser instance, and uses the Chrome DevTools Protocol over WebSocket channels to provide live remote interaction with already authenticated browser sessions. Operators can navigate sites, manage tabs, send keyboard and mouse input, view a live screencast, and export decrypted cookies, enabling covert abuse of active sessions for email, enterprise applications, cloud services, financial platforms, and cryptocurrency services while leaving the user’s visible browser largely unaffected. This makes AmnesiaStealer notable for combining conventional information theft with practical session hijacking and hands-on browser abuse that can reduce the defensive value of multi-factor authentication once a session is established.
AmnesiaStealer shows awareness of macOS version differences and includes legacy privacy-bypass and collection logic that is less effective on newer macOS releases. It has been compared with other macOS stealers such as Atomic Stealer, MacSync, and CrashStealer because of overlapping objectives and lure tradecraft, but it stands out for its builder-driven configuration and live browser-control stage. The malware is named after the “Amnesia Panel” backend associated with its operation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Steal cookies from Safari based on the macOS version, using a TCC bypass flaw (CVE-2020-9771) to target macOS machines running Catalina. | Cybersecurity researchers have disclosed details of a new macOS-oriented, Rust-based information stealer called AmnesiaStealer that's capable of hijacking Chromium web browsers to steal session data.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
AmnesiaStealer establishes persistence through a LaunchDaemon masquerading as an Apple crash reporting component
That command downloads and starts a multi-stage Rust-based payload while removing installation traces.
Operators can see what appears in the browser and send keyboard or mouse input back to it.
Instead of sorting through exported data later, an attacker can act while a session is valid, including viewing account pages, moving through sign-in flows, exporting decrypted cookies, or importing cookies into another session.
the malware gathers credentials, browser records, Apple Notes, Telegram session data, documents, wallet-related browser data, and keychain material. | It also tries to obtain each browser’s Safe Storage key from the login keychain, potentially helping the later module read protected browser information.
Stage one targets sixteen Chromium-family browsers, collecting cookies, login databases, history, bookmarks, extensions, Local State, Preferences, and related artifacts.
Operators can see what appears in the browser and send keyboard or mouse input back to it.
It also spawns a relay channel using WebSocket to accept operator commands and report the status back to the same endpoint. | It includes the following details - Command-and-control (C2) endpoints (i.e., "debug.allllowef[.]space/send/")
49 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A newly identified macOS information stealer delivered via ClickFix social engineering. It steals credentials, browser data, Apple Notes, Telegram session data, documents, wallet-related browser data, and keychain material, and includes a second-stage module that clones a victim browser profile into a hidden headless Chromium session for real-time abuse of authenticated sessions. It also establishes persistence via a disguised LaunchDaemon.
Related : AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions
A multi-stage Rust-based macOS infostealer delivered via ClickFix lures and counterfeit GitHub pages. It steals credentials, browser data, Apple Notes, Telegram session data, documents, wallet-related browser artifacts, and keychain contents, establishes LaunchDaemon persistence, and includes a Stage 2 browser streaming module that clones Chromium profiles and gives operators hidden interactive access to authenticated browser sessions through the Chrome DevTools Protocol.
A macOS infostealer delivered via a fake download and ClickFix-style user-executed Terminal command. It steals browser data, macOS Keychain data, Apple Notes, and Telegram data, and can optionally download a component ('stream_module') that copies a Chromium profile, launches a hidden browser instance, and enables remote interaction to preserve or abuse authenticated browser sessions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.