AmnesiaStealer Targets macOS Users via Fake GitHub Pages

A newly identified macOS malware, dubbed AmnesiaStealer, is actively targeting users through counterfeit GitHub download pages. This sophisticated campaign employs social engineering tactics to deceive users into executing malicious Terminal commands, leading to unauthorized access and data theft.

Deceptive Distribution Tactics

Security researchers have uncovered a fraudulent website that closely mimics GitHub’s interface, complete with the dark theme, Octocat logo, and a “Verified Publisher” badge. Instead of providing legitimate software downloads, the site presents a “Terminal installation” box with a one-click copy button. Users are instructed to open Terminal, paste the provided command, press Return, and enter their device password. This method, known as ClickFix, has been previously utilized to disseminate other macOS malware variants, indicating a recurring strategy among cybercriminals.

Malware Execution and Data Exfiltration

Upon execution of the malicious command, a concealed shell script downloads a password-protected ZIP archive, extracts a disguised binary into the /tmp directory, removes Apple’s quarantine flag, and launches the payload before erasing its traces. The malware then profiles the infected machine and displays a counterfeit system password prompt to capture the user’s credentials. With these credentials, it unlocks and exfiltrates sensitive data, including keychain entries, Apple Notes, Telegram sessions, browser data, and documents.

Advanced Control Capabilities

One of the most alarming features of AmnesiaStealer is its ability to grant attackers live, hidden control over the victim’s browser sessions. A component called stream_module, fetched on command from the attacker’s control panel, clones the victim’s browser profile, launches it in headless mode, and connects to the Chrome DevTools Protocol. This setup allows the attacker to view a live screencast of the session and exert full control over mouse, keyboard, and navigation functions. Consequently, attackers can operate the victim’s logged-in browser sessions, including email, banking, and social media accounts, without the victim’s awareness.

Interestingly, some of the malware’s attempts to bypass Apple’s privacy protections rely on techniques that have been patched in recent macOS versions. For instance, efforts to exploit APFS snapshot vulnerabilities, addressed in 2020, are recorded as failures in the malware’s debug logs. However, its core functionalities, such as credential theft and browser session hijacking, remain effective, particularly against users who have granted broader system permissions.

AmnesiaStealer exemplifies a growing trend where attackers combine convincing phishing pages with staged, remotely triggered payloads, rather than deploying a single static malware file. To mitigate such threats, users are advised to exercise caution and avoid pasting unknown commands into Terminal, especially those from unsolicited download prompts. Keeping macOS updated, enabling browser and endpoint threat protection, and treating any password prompt associated with a “software installer” with suspicion are essential precautions as this campaign continues to evolve.

As macOS gains popularity among professionals and general users alike, it becomes an increasingly attractive target for cybercriminals. The emergence of sophisticated malware like AmnesiaStealer underscores the importance of maintaining robust cybersecurity practices. Users should remain vigilant, verify the authenticity of download sources, and stay informed about evolving threats to safeguard their systems and personal information.