AmnesiaStealer: New Mac Malware Quietly Drains Passwords and Browser Sessions
A newly identified piece of malicious software targeting Apple Mac computers can lift saved passwords, browser cookies, and sensitive keychain data, and it is written in a programming language that makes it harder for security tools to catch.

Key points
- AmnesiaStealer is a newly discovered piece of malicious software built specifically to run on Apple Mac computers.
- It targets saved passwords, Apple's Keychain credential store, data from Chromium-based browsers such as Chrome and Edge, and Safari cookies.
- The malware is written in Rust, a programming language that security tools often struggle to scan effectively.
- No single attribution has been confirmed; researchers have not yet publicly linked the campaign to a known group.
A fresh piece of Mac-targeting malware called AmnesiaStealer has surfaced, and it is built to quietly scoop up nearly everything a person uses to log into their online life. Passwords, browser session cookies (the small files that keep you logged into websites without re-entering your password), Apple's Keychain (the built-in vault where Macs store credentials for apps and websites), and data from browsers built on Google's Chromium engine are all in scope. First reported by SecurityWeek, the campaign has drawn attention partly because of what is under the hood.
How does this malware actually work?
AmnesiaStealer is written in Rust, a modern programming language prized by developers for speed and reliability. It is increasingly popular among malware authors for a different reason: many antivirus and endpoint-protection tools find Rust-compiled code difficult to analyse, which gives the malware more time to operate before being flagged.
Once running on a victim's Mac, the software harvests credentials and session data, then sends it elsewhere. Stealing a session cookie is particularly damaging. It lets an attacker take over an active login on a site, including banking or email, without ever needing the victim's password.
The malware is classed as an infostealer, meaning its only job is to collect and exfiltrate information rather than lock files or demand payment.
Who is behind it, and how confident should we be?
Attribution here is thin. No vendor has publicly linked AmnesiaStealer to a tracked advanced persistent threat group, the term researchers use for organised hacking teams, often state-sponsored, that run long-running espionage or criminal operations. Without corroborating infrastructure overlaps or tooling similarities to a known cluster such as Kimsuky (tracked by CrowdStrike and others as a North Korean-linked group) or Lazarus Group, any nation-state attribution claim would sit below low confidence.
What is clear is capability: the malware can do real damage to an individual's accounts. Intent and operator identity remain open questions.
Should Mac users be worried, and what can they do?
Yes, to a reasonable degree. The widespread assumption that Macs do not get malware is outdated. Infostealers targeting macOS have grown steadily over the past two years.
Practical steps for ordinary users:
- Check where you download software. Most Mac malware arrives disguised as cracked apps or fake installers. Only install software from the Mac App Store or developers whose identity Apple has verified.
- Enable lockdown features. macOS has a setting called Gatekeeper that blocks unverified software. Make sure it is on in System Settings under Privacy and Security.
- Watch for unexpected logins. If an email service or bank notifies you of a login from an unfamiliar location, treat it seriously. Change your password and log out all other sessions immediately.
- Use a password manager with two-factor authentication. A stolen password is far less useful if a second verification step (a code sent to your phone, for example) is also required.
Researchers are still analysing AmnesiaStealer's full delivery chain, and further details on how victims first encounter the malware are expected as the investigation matures.



