AmnesiaStealer: New Mac Malware Quietly Drains Passwords and Browser Sessions
A newly identified piece of malicious software targeting Apple Mac computers can lift saved passwords, browser cookies, and sensitive keychain data, and it's written in a programming language that makes it harder for security tools to catch.

Key points
- AmnesiaStealer is a newly discovered piece of malicious software built specifically to run on Apple Mac computers.
- It targets saved passwords, Apple's Keychain credential store, data from Chromium-based browsers such as Chrome and Edge, and Safari cookies.
- The malware is written in Rust, a programming language that security tools often struggle to scan effectively.
- No single attribution has been confirmed; researchers haven't yet publicly linked the campaign to a known group.
A Mac-targeting infostealer called AmnesiaStealer has surfaced, built to quietly collect nearly everything a person uses to log into their online life. Passwords, browser session cookies (small files that keep you logged into websites without re-entering your password), Apple's Keychain (the built-in vault where Macs store credentials for apps and websites), and data from browsers built on Google's Chromium engine are all in scope. First reported by SecurityWeek, the campaign's drawn attention partly because of what's under the hood.
How does this malware actually work?
AmnesiaStealer is written in Rust, a modern programming language prized for speed and reliability. It's increasingly popular among malware authors for a different reason: many antivirus and endpoint-protection tools find Rust-compiled code difficult to analyse, giving the malware more time to operate before being flagged. We noted the same Rust-based evasion approach in our 31 July report on the HollowFrame and Matryoshka campaign, which targeted a law firm's Windows machines.
Once running on a victim's Mac, the software harvests credentials and session data, then exfiltrates them. Stealing a session cookie is particularly damaging: it lets an attacker take over an active login, including on banking or email services, without ever needing the victim's password.
Who is behind it, and how confident should we be?
Attribution is thin. No vendor has publicly linked AmnesiaStealer to a tracked advanced persistent threat group, the term researchers use for organised hacking teams, often state-sponsored, that run long-running espionage or criminal operations. Without corroborating infrastructure overlaps or tooling similarities to a known cluster, any nation-state claim would sit below low confidence. Kimsuky (tracked by CrowdStrike and others as North Korean-linked) and Lazarus Group are the kind of anchors analysts reach for, but neither has been invoked here.
Capability is clear enough. Intent and operator identity aren't.
Should Mac users be worried, and what can they do?
Yes, to a reasonable degree. The assumption that Macs don't get malware is outdated. Infostealers targeting macOS have grown steadily, and AmnesiaStealer is the kind of tool that does real damage to personal accounts before most users notice anything.
Practical steps:
- Check where you download software. Most Mac malware arrives disguised as cracked apps or fake installers. Only install software from the Mac App Store or Apple-verified developers.
- Enable Gatekeeper, the macOS feature that blocks unverified software. It lives in System Settings under Privacy and Security.
- Watch for unexpected logins. If a bank or email service flags a sign-in from an unfamiliar location, change your password and revoke all other active sessions immediately.
- Use a password manager alongside two-factor authentication. A stolen password is far less useful when a second verification step is also required.
Researchers are still tracing AmnesiaStealer's full delivery chain. How victims first encounter it remains an open question, and that answer matters: the fake Solana and TradingView sites we covered on 25 July show how convincingly malware can be wrapped in a legitimate-looking surface.



