EXECUTIVE SUMMARY:
Amnesia Stealer is a macOS-focused infostealer malware distributed through ClickFix-style social engineering techniques designed to trick users into executing malicious commands or scripts. The campaign targets macOS users by presenting fake system maintenance or verification prompts that appear legitimate, encouraging victims to initiate the infection process themselves. This approach allows the malware to bypass traditional security controls by relying on user interaction rather than direct exploitation of system vulnerabilities. Additionally, the malwares targeting of macOS environments highlights the importance of addressing platform-level security weaknesses such as CVE-2020-9771, a macOS Sandbox vulnerability that could allow unauthorized access to protected parts of the file system, potentially increasing the impact of malicious activity on affected systems.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Amnesia Stealer is a macOS-focused infostealer malware distributed through ClickFix-style social engineering techniques designed to trick users into executing malicious commands or scripts. The campaign targets macOS users by presenting fake system maintenance or verification prompts that appear legitimate, encouraging victims to initiate the infection process themselves. This approach allows the malware to bypass traditional security controls by relying on user interaction rather than direct exploitation of system vulnerabilities. Additionally, the malwares targeting of macOS environments highlights the importance of addressing platform-level security weaknesses such as CVE-2020-9771, a macOS Sandbox vulnerability that could allow unauthorized access to protected parts of the file system, potentially increasing the impact of malicious activity on affected systems.[emaillocker id="1283"]
The attack chain begins with malicious webpages that impersonate legitimate macOS utilities or system support pages and instruct users to perform specific actions. The ClickFix technique guides victims into executing a prepared script through macOS Script Editor instead of the commonly abused Terminal method. The triggered script executes obfuscated commands that download additional payloads from attacker-controlled infrastructure, decode the next-stage components, and deploy the infostealer binary. Once installed, the malware is capable of collecting sensitive information, including browser data, credentials, cryptocurrency wallet information, and other stored user data from the compromised macOS system.
Amnesia Stealer highlights the growing adoption of social engineering-based delivery methods against macOS environments, where attackers continuously modify execution techniques to evade security improvements. By abusing trusted macOS utilities and convincing users to authorize malicious actions, the campaign demonstrates the importance of user awareness, application control, and behavioral monitoring to detect and prevent infostealer infections.
THREAT PROFILE:
| Tactic | Technique Id | Technique | Sub-technique |
| Initial access | T1566.002 | Phishing | Spearphishing Link |
| Execution | T1059.003 | Command and Scripting Interpreter | Windows Command Shell |
| Persistence | T1543.003 | Create or Modify System Process | Windows Service |
| Credential access | T1555.003 | Credentials from Password Stores | Credentials from Web Browsers |
| Collection | T1005 | Data from Local System | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
MBC MAPPING:
| Objective | Behaviour ID | Behaviour |
| Anti-Behavioral Analysis | B0001 | Debugger Detection |
| Anti-Static Analysis | B0032 | Executable Code Obfuscation |
| Collection | E1560 | Archive Collected Data |
| B0028 | Cryptocurrency | |
| E1056 | Input Capture | |
| F0002 | Keylogging | |
| E1113 | Screen Capture | |
| Command and Control | B0030 | C2 Communication |
| Defense Evasion | F0001 | Software Packing |
| F0004 | Disable or Evade Security Tools | |
| F0005 | Hidden Files and Directories | |
| F0007 | Self Deletion | |
| F0015 | Hijack Execution Flow | |
| E1027 | Obfuscated Files or Information | |
| E1055 | Process Injection | |
| Discovery | B0013 | Analysis Tool Discovery |
| E1082 | System Information Discovery | |
| E1083 | File and Directory Discovery | |
| Execution | B0011 | Remote Commands |
| B0025 | Conditional Execution | |
| E1059 | Command and Scripting Interpreter | |
| Exfiltration | E1020 | Automated Exfiltration |
| Impact | B0022 | Remote Access |
| Lateral Movement | E1105 | Ingress Tool Transfer |
| Persistence | F0012 | Registry Run Keys / Startup Folder |
| E1564 | Hide Artifacts | |
| Cryptography Micro-objective | C0027 | Encrypt Data |
| C0031 | Decrypt Data | |
| Data Micro-objective | C0024 | Compress Data |
| C0053 | Decode Data | |
| File System Micro-objective | C0016 | Create File |
| C0047 | Delete File | |
| C0051 | Read File | |
| C0052 | Writes File | |
| Memory Micro-objective | C0007 | Allocate Memory |
| Operating System Micro-objective | C0036 | Registry |
| Process Micro-objective | C0017 | Create Process |
REFERENCES:
The following reports contain further technical details:
https://cybersecuritynews.com/amnesiastealer-macos-malware/
https://www.jamf.com/blog/amnesia-stealer-macos-infostealer-clickfix/
[/emaillocker]