Threat Advisory

AmnesiaStealer Campaign Utilizes Deceptive GitHub Pages to Harvest Keychain Details

Threat: Malware Campaign
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Amnesia Stealer is a macOS-focused infostealer malware distributed through ClickFix-style social engineering techniques designed to trick users into executing malicious commands or scripts. The campaign targets macOS users by presenting fake system maintenance or verification prompts that appear legitimate, encouraging victims to initiate the infection process themselves. This approach allows the malware to bypass traditional security controls by relying on user interaction rather than direct exploitation of system vulnerabilities. Additionally, the malwares targeting of macOS environments highlights the importance of addressing platform-level security weaknesses such as CVE-2020-9771, a macOS Sandbox vulnerability that could allow unauthorized access to protected parts of the file system, potentially increasing the impact of malicious activity on affected systems.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Amnesia Stealer is a macOS-focused infostealer malware distributed through ClickFix-style social engineering techniques designed to trick users into executing malicious commands or scripts. The campaign targets macOS users by presenting fake system maintenance or verification prompts that appear legitimate, encouraging victims to initiate the infection process themselves. This approach allows the malware to bypass traditional security controls by relying on user interaction rather than direct exploitation of system vulnerabilities. Additionally, the malwares targeting of macOS environments highlights the importance of addressing platform-level security weaknesses such as CVE-2020-9771, a macOS Sandbox vulnerability that could allow unauthorized access to protected parts of the file system, potentially increasing the impact of malicious activity on affected systems.[emaillocker id="1283"]

The attack chain begins with malicious webpages that impersonate legitimate macOS utilities or system support pages and instruct users to perform specific actions. The ClickFix technique guides victims into executing a prepared script through macOS Script Editor instead of the commonly abused Terminal method. The triggered script executes obfuscated commands that download additional payloads from attacker-controlled infrastructure, decode the next-stage components, and deploy the infostealer binary. Once installed, the malware is capable of collecting sensitive information, including browser data, credentials, cryptocurrency wallet information, and other stored user data from the compromised macOS system.

Amnesia Stealer highlights the growing adoption of social engineering-based delivery methods against macOS environments, where attackers continuously modify execution techniques to evade security improvements. By abusing trusted macOS utilities and convincing users to authorize malicious actions, the campaign demonstrates the importance of user awareness, application control, and behavioral monitoring to detect and prevent infostealer infections.

 

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.002 Phishing Spearphishing Link
Execution T1059.003 Command and Scripting Interpreter Windows Command Shell
Persistence T1543.003 Create or Modify System Process Windows Service
Credential access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Collection T1005 Data from Local System -
Command and control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel -

 

MBC MAPPING:

Objective Behaviour ID Behaviour
Anti-Behavioral Analysis B0001 Debugger Detection
Anti-Static Analysis B0032 Executable Code Obfuscation
Collection E1560 Archive Collected Data
B0028 Cryptocurrency
E1056 Input Capture
F0002 Keylogging
E1113 Screen Capture
Command and Control B0030 C2 Communication
Defense Evasion F0001 Software Packing
F0004 Disable or Evade Security Tools
F0005 Hidden Files and Directories
F0007 Self Deletion
F0015 Hijack Execution Flow
E1027 Obfuscated Files or Information
E1055 Process Injection
Discovery B0013 Analysis Tool Discovery
E1082 System Information Discovery
E1083 File and Directory Discovery
Execution B0011 Remote Commands
B0025 Conditional Execution
E1059 Command and Scripting Interpreter
Exfiltration E1020 Automated Exfiltration
Impact B0022 Remote Access
Lateral Movement E1105 Ingress Tool Transfer
Persistence F0012 Registry Run Keys / Startup Folder
E1564 Hide Artifacts
Cryptography Micro-objective C0027 Encrypt Data
C0031 Decrypt Data
Data Micro-objective C0024 Compress Data
C0053 Decode Data
File System Micro-objective C0016 Create File
C0047 Delete File
C0051 Read File
C0052 Writes File
Memory Micro-objective C0007 Allocate Memory
Operating System Micro-objective C0036 Registry
Process Micro-objective C0017 Create Process

 

REFERENCES:

The following reports contain further technical details:

https://cybersecuritynews.com/amnesiastealer-macos-malware/

https://www.jamf.com/blog/amnesia-stealer-macos-infostealer-clickfix/

[/emaillocker]
crossmenu