AMNESIASTEALER is a new macOS infostealer developed in Rust that targets users via counterfeit GitHub pages, utilizing a technique called ClickFix. The malware operates in three stages: it downloads and launches a payload, harvests sensitive information from the user's system, and ultimately provides attackers with live control over the victim's browser. During its operation, it captures passwords, cookies, and data from various applications, and can even manipulate browser sessions undetected.
The malware employs a stealth module to bypass security measures, and its infrastructure suggests a well-organized cyber operation rather than an isolated incident.