Particle.news
Download on the App Store

AmnesiaStealer: macOS Rust Stealer That Lets Attackers Run Hidden Live Browser Sessions

Jamf says the malware uses a remote 'stream' module to clone and control a victim's browser in real time, giving operators access to decrypted cookies and live interaction.

Overview

  • Jamf Threat Labs disclosed AmnesiaStealer on Friday, Aug. 14, 2026, after finding the stealer delivered by counterfeit GitHub pages that trick users into pasting Terminal commands.
  • The three-stage Rust chain first runs a short shell downloader, then prompts the user for their macOS login password to unlock and copy login and data-protection keychains for harvest.
  • A remotely fetched stream module clones the victim browser profile, launches a headless copy and uses the Chrome DevTools Protocol so attackers see a low-frame-rate screencast and send real-time keyboard, mouse and navigation commands.
  • The malware targets multiple Chromium-based browsers, overwrites per-browser Safe Storage keys so operators can decrypt later-saved credentials, attempts known macOS TCC bypasses, and persists via a LaunchDaemon that mimics Apple crash reporting.
  • Jamf links the payloads to an 'Amnesia Panel' command-and-control with Russian-language indicators and reused ClickFix lure templates, and recommends blocking suspicious web installs, monitoring pasted Terminal commands, and hunting for Safe Storage key tampering and unusual LaunchDaemons.