Researchers reported a new macOS infostealer, AmnesiaStealer, being spread through ClickFix-style social engineering that tricks users into copying and pasting a malicious command into Terminal, including via fake GitHub download pages. The multi-stage infection chain uses a Bash loader to profile the host and retrieve a processor-specific Mach-O payload written in Go, then steals browser passwords, Apple Keychain data, cached credentials, Telegram sessions, Apple Notes, documents, and other sensitive information from infected systems.
Investigators said the malware also includes cryptocurrency-theft functionality that can transfer wallet funds to attacker-controlled addresses, and a later-stage component, stream_module, can be fetched on demand to clone browser profiles and attach to the Chrome DevTools Protocol for covert access to already authenticated browser sessions. Huntress linked parts of the loader, payload-hosting, and command-and-control infrastructure to the Aeza Group, a sanctioned Russian bulletproof hosting provider tied to cybercrime, while Jamf noted some privacy-bypass methods are outdated on newer macOS releases even though the malware’s credential theft and session-hijacking features remain effective.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Huntress said it observed a new macOS infostealing malware campaign in June 2026. The ClickFix-style attack tricked users into pasting a malicious command into Terminal, launching a multi-stage infection chain.
Jamf reported that a later-stage component named stream_module can be fetched on command from the attacker panel. It clones the victim's browser profile, connects to the Chrome DevTools Protocol, and gives attackers hidden live control over logged-in browser sessions.
Jamf Threat Labs discovered and analyzed a macOS infostealer campaign using a fake GitHub page at github.aoitour[.]com and a ClickFix-style lure to get victims to run a malicious Terminal command. The malware, dubbed AmnesiaStealer, steals credentials, keychain data, browser information, Telegram sessions, Apple Notes, and documents.
In its analysis of the macOS infostealer campaign, Huntress linked the loader, payload hosting, and command-and-control infrastructure to the Aeza Group. The group was described as a sanctioned Russian bulletproof hosting provider associated with cybercrime.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
13 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcebleepingcomputer.com
Open sourcescworld.com
Open sourceinfosecurity-magazine.com
Open sourcethehackernews.com
Open sourcejamf.com
Open sourceinfosecurity-magazine.com
Open sourcetheevilbit.github.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.