MacOS AmnesiaStealer Enables Live, Authenticated Browser Session Hijacking

A new macOS information-stealer, AmnesiaStealer, uses a streaming module to clone a victim’s Chromium profile into a headless browser, enabling live, authenticated-session control across 16 Chromium-based browsers via WebSocket and the Chrome DevTools Protocol. It can exfiltrate cookies, saved logins, browsing history, wallets, notes, documents, and keychain data, and is distributed through ClickFix on a fake GitHub page with a password-protected ZIP. This marks the first documented macOS malware to pair a cloned Chromium profile with CDP-based live remote control, allowing attackers to view a live screencast (~3fps) and execute actions through the victim’s browser. Users should avoid unknown terminal commands and maintain strong security practices.
- New AmnesiaStealer macOS malware hijacks browser sessions via remote control BleepingComputer
- New macOS malware turns stolen browsers into attacker-controlled sessions csoonline.com
- Apple Mac Malware Lets Attackers Control Browser Sessions After Infection techrepublic.com
- AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS The Hacker News
- Fake GitHub download turns Safari & Chrome into a Keychain data stealer AppleInsider
Reading Insights
1
17
4 min
vs 5 min read
89%
952 → 106 words
Want the full story? Read the original article
Read on BleepingComputer