Cybersecurity

AmnesiaStealer Malware Allows Attackers to Remotely Control macOS Browser Sessions

Jamf discovered a new information-stealing malware targeting macOS users through ClickFix campaigns. It can copy Chromium profiles and run them in a hidden browser, allowing the attacker to control the user’s authenticated sessions. In addition to stealing browser data, the malware collects passwords, cryptocurrency wallets, Keychain data, and other files.

2026-08-16
4 min read
10 views
فريق تحرير certi.news
AmnesiaStealer Malware Allows Attackers to Remotely Control macOS Browser Sessions

A new piece of malware called AmnesiaStealer uses a technique that goes beyond stealing passwords and cookies, allowing the attacker to launch and directly control the victim’s authenticated browser session through a hidden browser on the infected macOS device.

Jamf, a company specializing in Apple device management and security, analyzed the malware’s distribution campaigns and found that it reaches users through ClickFix attacks. These campaigns rely on a fake download page that appears to be a GitHub page, then prompt the victim to download a password-protected ZIP archive. The command used in the attack executes a shell-written downloader, which downloads the archive and runs the Mach-O file containing the malware.

Cloning the Browser Session and Running It Without the User Seeing It

AmnesiaStealer’s most notable capabilities are provided by a component called stream_module, which can be loaded through the remote_stream command. This component copies the user profile from a Chromium browser, including its authentication state, then loads it into a hidden, headless browser instance on the infected device.

This mechanism supports seven Chromium-based browsers: Google Chrome, Microsoft Edge, Vivaldi, Arc, Opera, Brave, and Chromium. According to Jamf, these browsers share the same DevTools protocol, launch options, and cookie-encryption mechanism, making it easier for the malware to reuse the victim’s profile.

After launching the browser in hidden mode, the malware establishes a WebSocket channel with a relay server controlled by the attacker and sends a registration message containing the browser’s name and version. The operator can send commands to navigate, click, manage tabs, scroll, and use the keyboard, while receiving information about the session and tab states, as well as screen-stream frames at approximately three images per second.

What Changes in Practice?

A second WebSocket channel connects to the hidden Chromium instance through the webSocketDebuggerUrl address of the Chrome DevTools Protocol, or CDP. As a result, the attacker can import and export cookies, navigate websites, and interact with web portals using sessions that remain authenticated under the victim’s account.

This means the risk is not limited to extracting a saved file or password; the attacker may interact with websites as though the user were browsing them from their own device, while retaining identifiers associated with the browser, host, and network. Jamf describes this capability as turning the infected device into a live browser operated by the attacker and using the victim’s authenticated sessions.

Scope of the Targeted Data

AmnesiaStealer can collect data from 16 Chromium-based browsers, including cookies, saved login data, browsing history, bookmarks, extensions, and local state data. It also searches for cryptocurrency-wallet data by examining extensions and IndexedDB data.

The malware also collects the victim’s macOS password to access Keychain data, in addition to Apple Notes, Telegram sessions, documents, system information, and encrypted-wallet data.

Jamf pointed to a fallback mechanism when the malware runs on macOS 26 and cannot recover the current Chrome Safe Storage key. The malware replaces it with a value specified by the attacker, making previously stored cookies and passwords permanently unreadable while allowing the data to be decrypted later.

The Main Warning for Users

Jamf says that combining a cloned Chromium profile with direct control through CDP represents, based on what it has documented, a new case among macOS malware. Users are advised not to execute terminal commands they find online unless they fully understand their source and function, particularly when the commands appear within download pages or instructions that seem to be associated with a trusted service.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news