A new form of malware targeting macOS operating systems has been discovered by cybersecurity researchers. Dubbed AmnesiaStealer, this Rust-based information stealer is capable of hijacking Chromium web browsers to steal session data and take remote control over infected systems.
The macOS Rust-based AmnesiaStealer malware is being distributed through a clever ruse. Victims end up at a fake GitHub download website which initially seems to be genuine. This website has a title “Download for macOS” and indicates that it is issued by a verified publisher. Instead of downloading a legitimate product, however, users are shown a ClickFix style bait which prompts them to paste a Base64 encoded command into the macOS Terminal.
What makes this attack methodology so effective is its use of trust. A lot of Mac users will be familiar with using Terminal commands when downloading developer tools or solving problems. This malware uses the knowledge that people are used to downloading from GitHub to make it look like a legitimate download and put people at ease.
Now let me tell you all about the macOS based AmnesiaStealer malware that was discovered recently, its workings, and what Mac users need to know to protect themselves.
Main Properties of AmnesiaStealer
- AmnesiaStealer is a malware written in Rust for macOS systems
- Spread via fake GitHub download pages
- Utilizes ClickFix tricks with terminal commands to avoid warning pop-ups
- Credentials stolen include Keychain, web browser, Apple Notes, and Telegram session
- Remote control of Chromium browser sessions to perform hands-on-keyboard attack
- Features remote_stream plugin to hack into browsers
- Targets 16 Chromium browsers such as Google Chrome, Brave, and Microsoft Edge
Rising Dangers of Rust-based Malware
The latest discovery of AmnesiaStealer malware using Rust language on macOS is one of the many recent developments. In recent times, there has been an increase in cyber criminals using the modern systems programming language known as Rust to develop malware. This is due to the fact that Rust has some clear benefits for malware developers, which include being cross-platform, memory-safe, and producing compiled binaries that are not easily analyzed by security tools.
Malware written using Rust is more reliable and tends to crash less often than languages that came before it. That means it’s ideal for those wishing to write malicious code that runs smoothly and evades detection as long as possible.
The macOS Rust-based AmnesiaStealer malware is a prime example of this trend. The malware makes use of the strengths of Rust language along with advanced social engineering techniques for its creation.
Attack Methodology
AmnesiaStealer malware based on Rust on macOS uses an attack methodology comprising multiple stages which include both effectiveness and evasion.
Stage 1: The ClickFix Lure
In the first stage, a target visits a fake GitHub page, where it appears like a legitimate download site. It has all the elements of a normal download page, including a "Download for macOS" button and GitHub branding. But in reality, it’s a ClickFix trap which asks the user to enter a Base64 code in the macOS Terminal.
The user, thinking of installing a legitimate tool, enters the command and runs it. And this is the very step which starts off the whole attack process chain.
Stage 2: The Dropper Script
Once the command is executed, the macOS Rust-based AmnesiaStealer malware downloads a password-protected ZIP archive from a remote server. The archive contains the first-stage payload. Subsequently, the dropper script that was used as the first stage of infection deletes itself from the host to make itself hidden.
Self-deletion is a widespread evasion technique. The infection vector is gone, thus making it harder for the investigator to pinpoint where the infection came from.
Stage 3: The Rust Stealer
The extracted archive contains the first stage of the Mach-O binary, which is basically a Rust infostealer. The interesting thing about this binary is that it comes with an embedded and encrypted configuration file that can be modified by the threat actor without changing the code at build time. The malware can be customized easily for each campaign due to this "builder-driven" approach.
Stage 4: Remote Browser Control
The AmnesiaStealer malware that targets macOS operating systems has a robust remote_stream module. This module is not active by default. Instead, it is fetched on command from the C2 server. When activated, it gives the operator hidden, interactive control of the victim's browser.
What the Stealer Harvests
The macOS Rust-based AmnesiaStealer malware casts a wide net when it comes to data theft:
System Data:
- iCloud Keychain using captured system password
- Apple Notes content
- Telegram sessions
- Files with specific extensions:
- .txt, .pdf, .rtf, .doc
- .wallet, .key
- .jpg, .png, .csv
Chromium Browsers (16 targets):
- Google Chrome
- Brave
- Arc
- Microsoft Edge
- Opera
- Vivaldi
- Chromium
Stolen Browser Data:
- Cookies
- Login Data
- Web Data
- History
- Bookmarks
- Local State
- Preferences
- Extensions directory
Safari Data:
- Cookies (using CVE-2020-9771 TCC bypass)
- Works on Catalina and newer versions
- Requires Full Disk Access for newer macOS versions
Password Capture Approach
The AmnesiaStealer malware written in Rust language on macOS captures passwords using a very innovative approach in which social engineering is used instead of exploiting the vulnerabilities of the software:
The Prompt:
AmnesiaStealer malware shows the victim a native macOS prompt that looks like it comes from an installer. The malware asks the victim to enter their system password. Because this appears to be genuine and shown in the middle of the installation process, victims have no reason not to comply.
Validation:
Once the password is entered, the macOS Rust-based AmnesiaStealer malware validates it against the local directory service using the dscl command-line tool. Verification ensures that the right password is sent out to the attacker’s computer and hence improves the probability of getting a legitimate password stolen.
The Loop:
In case the password is wrong, a dialog loop is started that reads "Incorrect password. Please try again." This keeps on repeating till the right password is entered, thus compelling the user to provide their genuine credentials.
Fallback Path:
A fallback saves /tmp/tempAppleScript.scpt and runs osascript when the native method fails. But, in this particular case, the native path worked and no osascript was launched.
Storage of Password:
The captured password is used all along the chain. It is piped into sudo -S for privileged read access, used in security unlock-keychain -p command and is stored in cleartext both in the staging directory as pwd and as ~/.pwd in the user’s home directory.
The ClickLock Stealer Connection
The macOS Rust-based AmnesiaStealer malware shares similarities with another stealer family called ClickLock Stealer:
ClickLock Stealer:
- Also uses ClickFix technique
- Targets users in Europe, North America, Middle East, and Africa
- Spread via phishing pages
Common Behaviors:
- Both use ClickFix lures
- Both target macOS users
- Both capture system passwords
This connection suggests that the macOS Rust-based AmnesiaStealer malware may be part of a broader ecosystem of macOS threats that share techniques and infrastructure.
Persistence Technique
Persistence can be established by the macOS AmnesiaStealer malware that is coded in Rust:
- Root LaunchDaemon creation
- Pretends to be Apple’s crash reporting service
- Enables the malware to endure reboots
- Remains concealed in the system
Data Staging and Data Exfiltration
The AmnesiaStealer Mac malware executes the staging and exfiltration of data as follows:
Data Staging
- Data is stored in the /tmp/ folder
- Name of the folder has 25 randomly generated alphanumeric characters
- Randomization makes the search for the stolen data difficult
Data Exfiltration
- Data archive is moved to the C2 server
- URL of the C2 server is "debug.allllowef[.]space/send/"
Clipboard Hijack
The macOS Rust-based AmnesiaStealer malware has a clipboard hijacking module that targets cryptocurrency users:
- Module name: CLIPPER_ENABLED
- Cryptocurrency addresses targeted:
- Bitcoin, Bitcoin Cash, Ethereum
- TRON, Litecoin, Monero
- Solana, Ripple, Cosmos (ATOM)
Whenever a user copies cryptocurrency address to clipboard, the malware substitutes it with an attacker's address.
What Sets AmnesiaStealer Apart
Three distinct aspects set the macOS Rust-based AmnesiaStealer malware apart from other macOS stealers:
1. Builder-Driven Configuration:
Modification of the configuration is possible without any code change at the build level. Thus, it becomes easy for the attackers to configure the malware according to different campaigns.
2. OS Version-Based Techniques
The macOS Rust-based AmnesiaStealer malware uses varying techniques depending on the macOS version. From this perspective, it uses macOS bypasses that are no longer present in newer macOS versions.
3. Remote-Control Second Stage:
The remote_stream module enables live browser session hijacking. This is not an automated data dump. It is a hands-on-keyboard hidden browser session that gives attackers real-time control.
The Name "AmnesiaStealer"
The macOS Rust-based AmnesiaStealer malware gets its name from a login page located at the root of the C2 host:
- The page is named "Amnesia Panel"
- A failed login returns an error message in Russian
- Urges users to provide a correct login or password
- The Russian-language error message provides a clue about the operators' origin.
What Mac Users Should Do
The macOS Rust-based AmnesiaStealer malware poses a great risk and requires vigilance and prevention steps to be taken:
Prevention Steps:
- Use only trusted sources for downloading any software
- Watch out for GitHub download pages requesting Terminal commands
- Do not enter Base64 commands in Terminal unless you trust the source
- Be sure about the publisher of the software before installing it
- Ensure that your macOS is up to date
Detection:
- Check for unknown LaunchDaemons
- Look for unusual files in /tmp/
- Monitor for suspicious Terminal activity
- Check for the presence of ~/.pwd file
If Compromised:
- Change your system password immediately
- Change all browser passwords
- Log out of all browser sessions
- Review accounts for unauthorized activity
- Consider wiping and reinstalling macOS
The Researcher's Analysis
Thijs Xhaflaire of Jamf Threat Labs provided a detailed analysis of the macOS Rust-based AmnesiaStealer malware:
Key findings:
- "A working collector paired with a working browser-hijack stage"
- "Wrapped around a few dated bypasses"
- "What makes it worth tracking"
The malware delivers on its goals:
- Harvests credentials, browser data, and live sessions
- Provides effective remote control through browser hijacking
- Uses clever evasion techniques to avoid detection
Wrapping It Up
The macOS Rust-based AmnesiaStealer malware is a sophisticated threat that targets macOS users through clever social engineering. It makes use of ClickFix lures to harvest passwords, browsing data, and session tokens, and it provides remote control capabilities for the affected systems.
Key Takeaways:
- Rust-based malware called MacOS Stealer with advanced architecture
- Spread through fake GitHub sites that used ClickFix payloads
- Uses terminal commands to deploy the malware
- Keychain, Browser, Notes, and Telegram data stolen
- Part of browser hijacker which provides remote access
- Affects 16 Chromium-based browsers
- Has clipboard hijack feature for crypto stealing
Users of the operating system must make sure that every application that they download must be from trusted sources. Base64 code must not be used in the Terminal unless they are certain about its authenticity.
The macOS Rust-based AmnesiaStealer malware is a reminder that macOS threats are evolving and becoming more sophisticated.
FAQ Section
What is the macOS Rust-based AmnesiaStealer malware?
AmnesiaStealer is an macOS information stealer built on Rust and exploits ClickFix lure campaigns to steal the user’s data. The tool targets Keychain, browsers, and Telegram sessions, in addition to enabling remote browser hijacking.
What happens during the attack?
The victims visit the phishing GitHub page and are asked to execute the Base64 command using Terminal. This downloads a multi-stage payload that steals data and enables remote browser control.
What data does AmnesiaStealer steal?
It steals iCloud Keychain, Apple Notes, Telegram sessions, 16 Chromium-based browsers' information and system passwords. Moreover, it tries to steal cryptocurrencies from wallets via clipboard hijacking.
What is the remote_stream module?
It is a module that gives attackers interactive remote control over the victim's browser. It provides a live screencast and full input control through Chrome DevTools Protocol.
What should Mac users do?
Only download software from official sources. Never paste Base64 commands into Terminal. Be suspicious of GitHub download pages. Keep macOS updated.