Cybersecurity researchers have uncovered a sophisticated Mac malware campaign capable of stealing passwords and giving attackers remote control of web browsers, potentially exposing financial and cryptocurrency accounts.
Researchers at Jamf Threat Labs identified the malware as AmnesiaStealer, an information-stealing program that targets sensitive data stored on infected Macs.
The attack begins with social engineering rather than an automatic infection. Victims are directed to convincing fake GitHub pages featuring a bogus “Download for macOS” button. They are then persuaded to copy and run a malicious command in Terminal, which downloads the malware.
Once installed, AmnesiaStealer displays a fake macOS login prompt designed to capture the user’s password. Attackers can then attempt to access information stored in Keychain, Apple Notes, browser password vaults and files on the computer.
Researchers said the malware can also target Safari cookies by exploiting the older CVE-2020-9771 vulnerability on systems where it remains exploitable.
To remain active, AmnesiaStealer installs a background process designed to resemble Apple’s crash-reporting software. Information collected from the device is packaged into an archive and transmitted to infrastructure controlled by the attackers.
A particularly concerning feature is the malware’s second-stage browser hijacking capability.
When activated remotely, another component uses the Chrome DevTools Protocol to launch a concealed browser session and give attackers real-time control. The technique can target Chromium-based browsers including Google Chrome, Microsoft Edge, Brave and Opera.
By copying a victim’s existing browser profile, attackers may be able to access authenticated online sessions and interact with websites as though they were using the victim’s browser directly, potentially placing banking, cryptocurrency and other sensitive accounts at risk.
The campaign highlights the danger of instructions on unfamiliar websites asking Mac users to paste commands into Terminal, even when the page appears to be a legitimate software download site.


