AmnesiaStealer macOS Malware: Advanced Browser Session Hijacking via Remote Control and GitHub Supply Chain Attacks

AmnesiaStealer macOS Malware: Advanced Browser Session Hijacking via Remote Control and GitHub Supply Chain Attacks

Executive Summary

A new and highly sophisticated macOS malware, AmnesiaStealer, has emerged, leveraging advanced techniques to hijack browser sessions via remote control. Distributed through counterfeit GitHub download pages, AmnesiaStealer represents a significant escalation in the threat landscape for macOS users and organizations. This report provides a comprehensive analysis of the malware’s technical mechanisms, security implications, and the broader cyber perspective, offering actionable insights for both technical and executive audiences.

Introduction

The macOS ecosystem has traditionally been perceived as more secure than other operating systems, but recent developments such as AmnesiaStealer challenge this assumption. By combining credential theft, keychain access, and live browser session hijacking, AmnesiaStealer enables attackers to gain persistent, interactive access to sensitive online accounts. Its distribution through trusted third-party platforms like GitHub further underscores the growing risk of supply chain attacks and the need for robust third-party risk management.

Technical Analysis of AmnesiaStealer

AmnesiaStealer operates through a multi-stage infection process. The initial stage involves a shell script dropper, delivered via a fake GitHub page, which downloads and executes a password-protected ZIP archive containing the main payload. The core payload is a Rust-based universal Mach-O binary, capable of harvesting keychain data, browser credentials, Apple Notes, Telegram sessions, documents, and system information. Notably, it employs a native macOS password prompt to capture user credentials and attempts to bypass macOS security controls, including Full Disk Access and TCC (Transparency, Consent, and Control) protections.

The most innovative aspect of AmnesiaStealer is its streaming module, which clones the victim’s Chromium browser profile and launches it in headless mode. This allows attackers to interactively control the browser session via the Chrome DevTools Protocol (CDP), accessing authenticated web sessions and sensitive data in real time. The attacker receives a live screencast of the session and can drive it with full input capabilities, effectively turning the infected host into a live, operator-driven browser running the victim's authenticated sessions.

Security Implications and Practical Risks

The technical sophistication of AmnesiaStealer introduces several critical risks. By capturing the victim’s macOS password, the malware can access keychain data, browser profiles, Apple Notes, Telegram sessions, documents, and cryptocurrency wallet data. Its ability to collect data from 16 Chromium-based web browsers, combined with live session hijacking, enables attackers to bypass traditional security controls and gain access to sensitive online accounts without alerting the victim.

The use of legitimate browser binaries and the DevTools Protocol makes detection particularly challenging, as malicious activity is blended with normal browser operations. Because the malware launches a headless browser against a cloned profile, the victim’s visible browser remains untouched, further complicating detection and forensics. Additionally, the use of password-protected ZIP files and ad-hoc code signing helps AmnesiaStealer evade automated analysis and macOS Gatekeeper protections.

Supply Chain and Third-Party Dependencies

AmnesiaStealer is distributed via ClickFix campaigns using counterfeit GitHub pages, a technique previously observed in other macOS infostealers such as Atomic (AMOS) and MacSync. This highlights the persistent risk of supply chain attacks leveraging trusted third-party platforms and social engineering. The shared lure template across multiple malware families underscores the importance of continuous monitoring and risk assessment of third-party software and download sources.

Security Controls and Compliance Considerations

While AmnesiaStealer attempts to bypass macOS security controls, many of these bypasses are no longer effective on the latest macOS versions. For example, attempts to bypass TCC protections and grant Full Disk Access fail on macOS 26. Organizations are strongly advised to ensure that all macOS devices are updated to the latest version and that users are educated about the dangers of executing untrusted scripts or commands. Advanced behavioral monitoring and strict endpoint controls are essential to detect and prevent such sophisticated threats.

Industry Adoption and Detection Challenges

The malware’s reliance on legitimate browser binaries and the DevTools Protocol for remote control makes it difficult to distinguish malicious activity from normal user behavior. Because the headless browser operates on a cloned profile, the victim’s own browser remains unaffected and shows no signs of compromise. This stealthy approach complicates both detection and incident response, necessitating more advanced monitoring solutions that can identify anomalous browser activity and unauthorized remote control attempts.

Vendor Security Practices and Infrastructure

AmnesiaStealer employs several techniques to evade detection and analysis, including the use of password-protected ZIP archives and ad-hoc code signing. The archive is protected with the password “dulin,” which defeats automated unpacking and inline inspection. These practices, combined with the use of counterfeit GitHub pages for distribution, highlight the evolving tactics of threat actors targeting the macOS ecosystem.

Cyber Perspective

From a cyber defense standpoint, AmnesiaStealer represents a significant escalation in macOS malware capabilities. Its combination of credential theft, keychain access, and live browser session hijacking allows attackers to bypass traditional security controls and maintain persistent, interactive access to sensitive accounts. The use of legitimate browser binaries and the DevTools Protocol for remote control makes detection and forensics more challenging, as malicious activity is seamlessly integrated with normal browser operations.

For defenders, this underscores the need for advanced behavioral monitoring, strict endpoint controls, and comprehensive user education to prevent social engineering attacks. For attackers, AmnesiaStealer opens new avenues for account takeover, lateral movement, and data exfiltration, particularly in environments where browser-based authentication is prevalent. The broader market impact is likely to be an increased focus on macOS endpoint security, browser session monitoring, and supply chain risk management.

About Rescana

Rescana’s Third-Party Risk Management (TPRM) solutions empower organizations to identify, assess, and mitigate risks associated with supply chain attacks, third-party software, and social engineering campaigns. Our platform delivers continuous monitoring, automated risk assessments, and actionable insights to ensure your vendors and partners adhere to the highest security standards. With Rescana, you can proactively manage your third-party ecosystem and reduce your exposure to emerging threats.

We are happy to answer any questions at info@rescana.com.