Daily Security Intel

Archives
Log in
Subscribe
August 17, 2026

[SecurityIntel] 17 Aug | AmnesiaStealer macOS Malware Hijacks Browser Sessions

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Monday, August 17, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

HIGH

THREAT OF THE DAY

AmnesiaStealer macOS Malware Hijacks Browser Sessions

HIGH

5

C2 IPs

40

OTX IOCs

6

ARTICLES

■ ANALYST TLDR

Today's threat landscape is highlighted by the emergence of AmnesiaStealer, a new macOS information-stealing malware that utilizes ClickFix social engineering lures to hijack browser sessions via a remote streaming module. Additionally, cryptocurrency hardware wallet provider SafePal suffered a data breach exposing the order details of nearly 40,000 customers, while Threema and Anthropic's Claude experienced major service disruptions. Organizations must also prioritize updating Wireshark to version 4.6.8 to remediate 28 newly patched security vulnerabilities.

■ CRITICAL STORIES

HIGH#1

New AmnesiaStealer macOS malware hijacks browser sessions via remote control

This new infostealer targets macOS users through ClickFix social engineering attacks and includes a unique streaming module that allows attackers to interactively control the victim's web browser in real-time.

INFO#2

SafePal data breach impacts 39,798 customers, stolen info for sale

A vulnerability in the hardware wallet provider's system was exploited to steal customer order information, exposing sensitive user data to potential targeted phishing and physical security risks.

INFO#3

Large-scale DDoS attacks disrupted Threema secure messaging service

Distributed denial-of-service attacks successfully disrupted the secure communications of Threema users, highlighting the ongoing threat of availability-disrupting attacks against secure messaging platforms.

HIGH#4

Wireshark 4.6.8 Released

The latest update addresses 28 security vulnerabilities and 25 bugs, representing a significant attack surface reduction for network analysts and organizations running the packet analysis tool.

■ CVEs IDENTIFIED

[CVE-TBD-WIRESHARK]

Wireshark Foundation Wireshark (prior to 4.6.8) — Multiple vulnerabilities including denial of service and potential code execution

High

[CVE-TBD-SAFEPAL]

SafePal Hardware Wallet Order System — Data breach exposing customer order information via exploit

Medium

■ THREAT ACTORS

Unknown Threat Actor

Cybercriminal

Exploited SafePal flaw to steal and sell customer order data

Unknown Threat Actor

Cybercriminal

Deploying AmnesiaStealer macOS malware via ClickFix social engineering

Unknown Threat Actor

Hacktivist / Cybercriminal

Launched large-scale DDoS attacks disrupting Threema secure messaging

■ ATT&CK TTPs

T1204.001
User Execution: Malicious Link | ClickFix social engineering lure used to deliver AmnesiaStealer on macOS
T1185
Browser Session Hijacking | AmnesiaStealer utilizes a streaming module to interactively control the victim's web browser
T1048
Exfiltration Over Alternative Protocol | AmnesiaStealer exfiltrates browser session data and credentials
T1498
Network Denial of Service | DDoS attacks targeting Threema secure messaging service
T1190
Exploit Public-Facing Application | Flaw exploited in SafePal's infrastructure to steal customer data

■ PATCH PRIORITY

[P2 PATCH NOW]≤72h

Wireshark — Fixes 28 security vulnerabilities and 25 bugs in the packet analysis tool — SANS

[P3 PATCH NOW]≤1 week

SafePal — Remediate the exploited flaw in the order system to prevent further data exposure — BleepingComputer

■ RECOMMENDED ACTIONS TODAY

1[P1] Update Wireshark to version 4.6.8 immediately to remediate 28 vulnerabilities [CVE-TBD-WIRESHARK]
2[P2] Educate macOS users on ClickFix social engineering tactics to prevent the installation of AmnesiaStealer malware
3[P2] SafePal customers should monitor for targeted phishing attempts and credential stuffing using leaked order details [CVE-TBD-SAFEPAL]
4[P3] Implement robust DDoS mitigation strategies and rate-limiting to protect communication services like Threema from service disruption
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 18 Aug | Active Exploitation of macOS Screen Sharing Vulnerability Older → [SecurityIntel] 16 Aug | Evooo1Bot Botnet Recruits Routers as SOCKS5 Relays
Powered by Buttondown, the easiest way to start and grow your newsletter.