Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
To steal Safari cookies and access the TCC database, the malware uses an old TCC bypass (CVE-2020-9771). On macOS 26, the attack works only if the Terminal or the malware process already has Full Disk Access. | The fake download page lures victims into pasting a command into Terminal, which leads to the newly discovered AmnesiaStealer being installed.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Cyberattack prevention service Security researchers at Jamf Threat Labs discovered the campaign after spotting a counterfeit site at github.aoitour[.]com that near-perfectly copies GitHub’s dark theme, Octocat logo, and “Verified Publisher” badge.
This gives the attacker a live screencast of the session along with full mouse, keyboard, and navigation control, effectively letting them operate the victim’s logged-in browser sessions, email, banking, and social media without the victim ever seeing anything change on their own screen.
After execution, the malware performs reconnaissance, prompts the user to provide their login password and validates it locally...
The Rust-based macOS infostealer harvests users’ passwords, keychain information, Chromium-based browser data, and Safari cookies.
The Rust-based macOS infostealer harvests users’ passwords, keychain information... copies login and data-protection keychains...
This is followed by a Rust-based infostealer that profiles the machine, displays a fake native “Installer” password prompt to capture the login credential, and uses it to unlock the keychain, Apple Notes, Telegram sessions, browser data, and documents.
...harvests Chromium-based browser databases, Apple Notes, and documents.
This gives the attacker a live screencast of the session along with full mouse, keyboard, and navigation control, effectively letting them operate the victim’s logged-in browser sessions, email, banking, and social media without the victim ever seeing anything change on their own screen.
After execution, the malware performs reconnaissance, prompts the user to provide their login password and validates it locally...
This gives the attacker a live screencast of the session along with full mouse, keyboard, and navigation control, effectively letting them operate the victim’s logged-in browser sessions, email, banking, and social media without the victim ever seeing anything change on their own screen.
The malware is named after the “Amnesia Panel” backend it communicates with, and its embedded configuration is unlocked with the key 4mn3s1a_2o26!xK.
If it receives a remote_stream command, the malware downloads and runs a stream module...
The final stream module, which is executed on demand, is an interactive remote-control component that uses the Chrome DevTools Protocol (CDP) to launch a headless copy of the browser, creating a relay channel through which the attacker can control the victim’s browser session.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-stage Rust-based macOS infostealer distributed via counterfeit GitHub download pages in ClickFix attacks. It harvests passwords, keychain data, Chromium browser data, Safari cookies, Apple Notes, and documents; attempts TCC bypasses; exfiltrates archived data to C2; installs a LaunchDaemon for persistence; and can download a second-stage remote-control module that uses Chrome DevTools Protocol to provide interactive control over the victim’s browser session.
A macOS infostealer delivered through a fake GitHub ClickFix-style page that tricks users into pasting a malicious Terminal command. It downloads and launches payloads, captures the user’s login password via a fake installer prompt, steals keychain data, Apple Notes, Telegram sessions, browser data, and documents, and can fetch a third-stage module that clones the victim’s browser profile and uses the Chrome DevTools Protocol for hidden live browser-session control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.