A multi-stage macOS info stealer based on Rust was distributed via a fake GitHub download page in the latest ClickFix attacks, Jamf reports.
The fake download page lures victims into entering a command into the terminal, which leads to the newly discovered AmnesiaStealer is installed.
As part of a three-stage infection chain, a shell script is executed to extract and execute the payload, the info stealer collects data, and a third module is executed on command to provide interactive control over victims’ browsers.
“Its goals overlap with families like Atomic (AMOS), MacSync, and CrashStealer. Three features distinguish it: compiler-driven configuration, branching OS version logic that reaches macOS patched bypasses, and the second stage of remote control,” notes Jamf.
Once executed, the malware performs reconnaissance, prompts the user to provide their login password and validates it locally, copies login and data security keys, and collects browser databases based on Chromium, Apple Notes, and documents.
AmnesiaStealer also attempts to bypass the Transparency, Consent and Control (TCC) framework to obtain a Safari cookie and full disk access, back up the collected data and send it to the Command and Control (C&C) server, and install LaunchDaemon for persistence.
If it receives a remote_stream command, the malware downloads and executes a streaming module that clones the victim’s browser profile and runs it headless to give attackers full control over the browser session.
The information thief targeted six Chromium-based browsers, including Chrome, Brave, Arc, and Edge, and was observed overwriting the safe-store key for each browser in the login keychain with a value controlled by the attacker, making previously saved passwords and cookies unrecoverable.
“The malware accepts this loss: it can’t recover the existing macOS 26 key, it exchanges the victim’s saved data with a key the operator already knows, so anything encrypted after that can be decrypted by the operator,” notes Jamf.
To steal Safari cookies and access the TCC database, the malware uses an old TCC bypass (CVE-2020-9771). In macOS 26, the attack only works if the terminal or malware process already has full access to the disk.
The final on-demand streaming module is an interactive remote control component that uses the Chrome DevTools Protocol (CDP) to launch a headless copy of the browser, creating a relay channel through which the attacker can control the victim’s browser session.
“The operator gets a live screencast of the session at about 3 frames per second and can control it with a full set of inputs: keyboard, mouse, scrolling, navigation and tab control. These are translated into CDP calls against the headless browser in real time. This is a hidden keyboard browser session, not an automated dump,” notes Jamf.
Related: Hidden ‘City-Forum’ attacks target Salesforce and ServiceNow with custom toolset
Related: Banned extension for stealing AI chats returns to Chrome store, resumes malicious activities
Related: Mozilla issues new GPG key for Firefox following disclosure
Related: ‘Ghostjacking’ attack uses poisoned logs to make AI agents evil