SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefMonday, August 17, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL HIGH |
|
THREAT OF THE DAY AmnesiaStealer macOS Malware Hijacks Browser Sessions | HIGH |
|
5 C2 IPs | 40 OTX IOCs | 6 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is highlighted by the emergence of AmnesiaStealer, a new macOS information-stealing malware that utilizes ClickFix social engineering lures to hijack browser sessions via a remote streaming module. Additionally, cryptocurrency hardware wallet provider SafePal suffered a data breach exposing the order details of nearly 40,000 customers, while Threema and Anthropic's Claude experienced major service disruptions. Organizations must also prioritize updating Wireshark to version 4.6.8 to remediate 28 newly patched security vulnerabilities. |
|
■ CRITICAL STORIES New AmnesiaStealer macOS malware hijacks browser sessions via remote control This new infostealer targets macOS users through ClickFix social engineering attacks and includes a unique streaming module that allows attackers to interactively control the victim's web browser in real-time. |
SafePal data breach impacts 39,798 customers, stolen info for sale A vulnerability in the hardware wallet provider's system was exploited to steal customer order information, exposing sensitive user data to potential targeted phishing and physical security risks. |
Large-scale DDoS attacks disrupted Threema secure messaging service Distributed denial-of-service attacks successfully disrupted the secure communications of Threema users, highlighting the ongoing threat of availability-disrupting attacks against secure messaging platforms. |
Wireshark 4.6.8 Released The latest update addresses 28 security vulnerabilities and 25 bugs, representing a significant attack surface reduction for network analysts and organizations running the packet analysis tool. |
|
■ CVEs IDENTIFIED [CVE-TBD-WIRESHARK] Wireshark Foundation Wireshark (prior to 4.6.8) — Multiple vulnerabilities including denial of service and potential code execution |
[CVE-TBD-SAFEPAL] SafePal Hardware Wallet Order System — Data breach exposing customer order information via exploit |
|
■ THREAT ACTORS Unknown Threat Actor | Cybercriminal |
Exploited SafePal flaw to steal and sell customer order data |
Unknown Threat Actor | Cybercriminal |
Deploying AmnesiaStealer macOS malware via ClickFix social engineering |
Unknown Threat Actor | Hacktivist / Cybercriminal |
Launched large-scale DDoS attacks disrupting Threema secure messaging |
|
|
|
■ ATT&CK TTPs | T1204.001 | | User Execution: Malicious Link | ClickFix social engineering lure used to deliver AmnesiaStealer on macOS |
| T1185 | | Browser Session Hijacking | AmnesiaStealer utilizes a streaming module to interactively control the victim's web browser |
| T1048 | | Exfiltration Over Alternative Protocol | AmnesiaStealer exfiltrates browser session data and credentials |
| T1498 | | Network Denial of Service | DDoS attacks targeting Threema secure messaging service |
| T1190 | | Exploit Public-Facing Application | Flaw exploited in SafePal's infrastructure to steal customer data |
|
■ PATCH PRIORITY Wireshark — Fixes 28 security vulnerabilities and 25 bugs in the packet analysis tool — SANS |
SafePal — Remediate the exploited flaw in the order system to prevent further data exposure — BleepingComputer |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Update Wireshark to version 4.6.8 immediately to remediate 28 vulnerabilities [CVE-TBD-WIRESHARK] |
| 2 | [P2] Educate macOS users on ClickFix social engineering tactics to prevent the installation of AmnesiaStealer malware |
| 3 | [P2] SafePal customers should monitor for targeted phishing attempts and credential stuffing using leaked order details [CVE-TBD-SAFEPAL] |
| 4 | [P3] Implement robust DDoS mitigation strategies and rate-limiting to protect communication services like Threema from service disruption |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |