MacOS AmnesiaStealer Enables Live, Authenticated Browser Session Hijacking

1 min read
Source: BleepingComputer
MacOS AmnesiaStealer Enables Live, Authenticated Browser Session Hijacking
Photo: BleepingComputer
TL;DR

A new macOS information-stealer, AmnesiaStealer, uses a streaming module to clone a victim’s Chromium profile into a headless browser, enabling live, authenticated-session control across 16 Chromium-based browsers via WebSocket and the Chrome DevTools Protocol. It can exfiltrate cookies, saved logins, browsing history, wallets, notes, documents, and keychain data, and is distributed through ClickFix on a fake GitHub page with a password-protected ZIP. This marks the first documented macOS malware to pair a cloned Chromium profile with CDP-based live remote control, allowing attackers to view a live screencast (~3fps) and execute actions through the victim’s browser. Users should avoid unknown terminal commands and maintain strong security practices.

Share this article

Want the full story? Read the original reporting

Read on BleepingComputer