← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 14, 2026 · 08:43via Security Affairs

AmnesiaStealer Gives Attackers Live Control of Victims’ macOS Browsers

Brief

AmnesiaStealer targets macOS users through fake GitHub pages, stealing passwords, cookies and data while giving attackers live control of the browser.

Jamf Threat Labs researchers disclosed AmnesiaStealer, a new multi-stage Rust-based macOS infostealer that spread through a counterfeit GitHub download page using the ClickFix technique.

The lure looks convincing: correct GitHub dark theme, Octocat logo, “Verified Publisher” badge, and instead of a download button, it asks the visitor to paste a Terminal command. The same fake GitHub template has been observed in Atomic Stealer and MacSync campaigns, which means the lure infrastructure is shared across multiple malware families.

“AmnesiaStealer runs in three stages: The first is a shell script that downloads and launches the payload. The second is a Rust infostealer that harvests the keychain, browsers, Apple Notes and Telegram.

Read more on Security Affairs