# Threat Intel Brief — August 17, 2026
TL;DR
- AmnesiaStealer, a new macOS infostealer, hijacks browser sessions via remote control and permanently corrupts credential storage on macOS 26 systems.
- Evooo1Bot, a Mirai-based Linux botnet, is actively converting internet-facing gateway devices into SOCKS5 proxy relays for malicious traffic.
- SafePal cryptocurrency wallet provider disclosed a data breach affecting approximately 39,798 customers; stolen order information is now being sold by threat actors.
- Threema encrypted messaging service suffered coordinated large-scale DDoS attacks causing severe disruptions for cloud-hosted users across multiple countries.
Critical Threats
AmnesiaStealer: macOS Session Hijacking via Remote Browser Control
What happened
A sophisticated information-stealing malware targeting macOS users has emerged, distributed through ClickFix social engineering campaigns using fake GitHub download pages. AmnesiaStealer employs a novel streaming module that launches a headless Chromium browser on the victim's machine, providing attackers with real-time remote control capabilities. The malware targets 16 Chromium-based browsers including Chrome, Edge, Brave, Opera, and Arc. Attackers gain a live screencast at three frames per second with full keyboard and mouse control, enabling interactive session hijacking while appearing to originate from the legitimate user's device and network.
Impact
AmnesiaStealer represents a significant escalation in macOS threats due to its real-time session hijacking capabilities. Unlike traditional infostealers that exfiltrate static credentials, this malware enables attackers to interact directly with authenticated web sessions, bypassing multi-factor authentication and appearing as legitimate traffic from the victim's IP address. The malware harvests passwords, keychain data, Apple Notes, Telegram sessions, documents, and cryptocurrency wallets. On macOS 26 systems, AmnesiaStealer permanently corrupts Chrome Safe Storage encryption keys, rendering all stored credentials unrecoverable even after malware removal. Organizations face risks of unauthorized access to corporate cloud services, email systems, financial platforms, and cryptocurrency holdings.
Recommendations
- Implement application allowlisting on macOS endpoints and block execution of password-protected ZIP archives from unverified sources
- Deploy EDR monitoring to detect headless browser launches with debugging flags such as
--remote-debugging-port,--user-data-dir, or--headless - Monitor network traffic for suspicious outbound WebSocket connections to non-standard ports or unknown relay servers, particularly when correlated with browser process activity
- Conduct immediate user awareness training emphasizing the danger of executing terminal commands from untrusted online sources, especially those involving curl, base64 decode, or shell script execution
- Force password resets and revoke active sessions for any users who may have executed ClickFix commands or downloaded files from suspicious GitHub pages
Evooo1Bot: Linux Gateway Devices Weaponized as Proxy Infrastructure
What happened
Security researchers have identified a new Mirai-based modular botnet actively targeting internet-facing Linux gateway devices. Evooo1Bot compromises routers, firewalls, and edge appliances to convert them into SOCKS5 traffic relay nodes. The botnet leverages the modular architecture typical of Mirai variants, likely exploiting default credentials, weak passwords, or previously disclosed vulnerabilities common to gateway devices.
Impact
Compromised gateway devices become unwitting participants in malicious proxy infrastructure, enabling attackers to relay traffic through victim networks while maintaining anonymity. This infrastructure can facilitate credential stuffing attacks, spam distribution, further lateral movement, or other malicious activities that appear to originate from legitimate organizational IP addresses. Organizations face IP reputation damage, bandwidth abuse, potential legal liability for traffic originating from their networks, and regulatory scrutiny. Detection is particularly challenging because legitimate gateway traffic patterns obscure malicious relay activity, and many organizations lack visibility into the internal operations of edge devices.
Recommendations
- Conduct immediate audits of all internet-facing Linux gateway devices including routers, firewalls, and VPN appliances; enforce strong authentication and eliminate default credentials
- Monitor outbound connections from gateway devices for unusual SOCKS5 proxy traffic on TCP port 1080 or non-standard ports, and investigate unexpected external connections
- Restrict management interfaces on edge devices to trusted IP ranges only; disable unnecessary services such as Telnet and enforce SSH with key-based authentication
- Implement network segmentation to isolate gateway devices from internal networks and deploy egress filtering to block unauthorized proxy traffic
- Review gateway device logs for indicators of compromise including unauthorized login attempts, new user accounts, or unexpected process execution; consider firmware reinstallation if compromise is suspected
SafePal Data Breach: Customer Order Information Compromised
What happened
SafePal, a cryptocurrency hardware wallet provider, disclosed a data breach affecting approximately 39,798 customers. A threat actor exploited a vulnerability to steal customer order information and is now attempting to sell the stolen data on underground markets.
Impact
Compromised customer order information typically includes names, shipping addresses, email addresses, phone numbers, and order details. While the breach notification does not indicate that private keys or cryptocurrency holdings were directly compromised, the stolen data enables targeted phishing campaigns, SIM-swapping attacks, and physical security threats against cryptocurrency holders. Threat actors can leverage order information to craft convincing social engineering attacks impersonating SafePal support, potentially leading to credential theft or malware installation. Customers face increased risk of targeted attacks due to their identified association with cryptocurrency holdings.
Recommendations
- If your organization uses SafePal devices, notify affected users immediately and provide guidance on recognizing phishing attempts impersonating SafePal support
- Advise users to be vigilant for targeted phishing emails, SMS messages, or phone calls referencing their SafePal orders or requesting account verification
- Recommend users enable additional security measures on accounts associated with their SafePal email addresses, including unique passwords and hardware-based multi-factor authentication
- Monitor for suspicious activity on email accounts and phone numbers potentially exposed in the breach, particularly SIM-swap attempts
- Consider alternative communication channels for cryptocurrency-related activities to reduce correlation between personal contact information and digital asset holdings
Threat Actor Activity
No specific threat actor attribution was disclosed for the incidents in this reporting period. The AmnesiaStealer campaign uses distribution infrastructure previously associated with Atomic and MacSync infostealer operations, suggesting potential overlap in threat actor tooling or infrastructure. The Evooo1Bot botnet follows established Mirai operational patterns, indicating either a Mirai variant operator or a distinct threat actor leveraging publicly available Mirai source code. The coordinated DDoS attacks against Threema demonstrate sophisticated operational capabilities including continuous tactical adaptation to evade mitigation, but no attribution has been published.
Geopolitical Context
The large-scale DDoS attacks against Threema encrypted messaging service raise questions about potential state-sponsored or politically motivated targeting. Threema is widely used by privacy-conscious users, journalists, activists, and organizations requiring secure communications. The timing and sophistication of the coordinated attacks, which targeted both the application layer and upstream colocation infrastructure, suggest a well-resourced adversary. Users in Switzerland, India, and China reported outages, though the geographic distribution of impact may reflect user base distribution rather than targeting criteria. The attack's focus on disrupting encrypted communications infrastructure aligns with patterns observed in state-sponsored operations aimed at degrading secure communication channels.
Recommended Actions
Immediate (0-24 hours)
- Audit all internet-facing Linux gateway devices for default credentials and unauthorized access; monitor for SOCKS5 proxy activity
- Deploy detection rules for headless browser launches with debugging flags on macOS endpoints
- Review SafePal customer communications and prepare user notifications regarding phishing risks
- Verify Threema service status if used for critical organizational communications
Short-term (24-72 hours)
- Implement application allowlisting on macOS systems and block password-protected archives from untrusted sources
- Conduct user awareness training on ClickFix social engineering techniques and terminal command execution risks
- Review and restrict management interface access on all edge network devices
- Assess DDoS mitigation capabilities with colocation and cloud service providers
This week
- Deploy network segmentation to isolate gateway devices and implement egress filtering
- Evaluate Threema On-Prem or alternative secure messaging platforms for business continuity planning
- Review incident response procedures for data breach notification and customer communication
- Conduct tabletop exercises for DDoS scenarios affecting critical communication platforms
Watch List
- ClickFix campaigns: Monitor for evolution of social engineering techniques using fake GitHub pages or software download portals targeting macOS users
- Mirai botnet variants: Track new Mirai-based botnets and their targeting of IoT and gateway devices; review threat intelligence for disclosed vulnerabilities in edge devices
- Cryptocurrency platform targeting: Increased focus on cryptocurrency wallet providers, exchanges, and related services for data theft and customer targeting
- Encrypted messaging disruption: Potential continuation of DDoS campaigns against secure communication platforms; monitor for similar attacks against Signal, Wire, or other encrypted messaging services
Sources
- BleepingComputer: SafePal data breach impacts 39,798 customers, stolen info for sale
- BleepingComputer: Large-scale DDoS attacks disrupted Threema secure messaging service
- BleepingComputer: New AmnesiaStealer macOS malware hijacks browser sessions via remote control
- BleepingComputer: New Evooo1Bot Linux botnet turns routers into traffic relay nodes
---
*This threat intelligence brief is current as of August 17, 2026. Threat landscapes evolve rapidly; organizations should maintain continuous monitoring and adapt defensive postures accordingly.*
