V-Help
← All news
Security

AmnesiaStealer: New macOS Malware Hijacks Browser Sessions via Remote Control

AmnesiaStealer: New macOS Malware Hijacks Browser Sessions via Remote Control

Photo: BleepingComputer

Quick answer

AmnesiaStealer is a new macOS malware that steals data from 16 Chromium-based browsers and allows attackers to remotely control authenticated sessions via a hidden browser.

Researchers at Jamf have identified a new macOS malware called AmnesiaStealer. It spreads via ClickFix phishing attacks, masquerading as legitimate software on a fake GitHub page. After downloading and unpacking a password-protected ZIP archive, the malware executes a script that downloads the primary payload—a Mach-O file.

AmnesiaStealer features a unique capability: it can copy user profiles from Chromium-based browsers, including Google Chrome, Microsoft Edge, Brave, and others, then load them into a hidden browser on the infected device. This allows attackers to access authenticated sessions of victims while preserving browser, host, and network identifiers. The malware also steals passwords, cryptocurrency wallet data, Apple Notes, and macOS Keychain information.

A distinctive feature of AmnesiaStealer is its stream_module, which enables remote browser control. Attackers can interact with sessions in real time, receiving a screen feed at approximately 3 frames per second. This allows them to navigate, input keystrokes and mouse actions, and export or import cookies. The module leverages the Chrome DevTools Protocol (CDP), previously exploited by other malware but now used for interactive session control on macOS.

Jamf experts note that AmnesiaStealer can bypass Chrome Safe Storage protection on macOS 26 by replacing the encryption key with its own. This renders previously saved cookies and passwords inaccessible to the user while enabling attackers to decrypt the data later. To defend against such attacks, users should avoid running unverified terminal commands and employ specialized macOS security solutions.

Common questions

How does AmnesiaStealer spread?
The malware spreads through ClickFix phishing campaigns using fake GitHub pages that prompt users to download a password-protected ZIP archive containing the malicious payload.
What data does AmnesiaStealer steal?
AmnesiaStealer collects data from 16 Chromium browsers, including passwords, cookies, browsing history, cryptocurrency wallets, Apple Notes, Telegram data, and macOS Keychain information.
How can users protect themselves from AmnesiaStealer?
Avoid executing unverified terminal commands, use reputable antivirus solutions, and keep your macOS and software up to date to mitigate risks.
Share:

Dzen feed: /feed/dzen.xml · RSS: /feed.xml

Why trust this

Prepared by the V-Help editorial team from the primary source with a published date.

Published by: V-Help.ru news desk

Source: BleepingComputer