New Mac Malware Hijacks Browser Sessions via Remote Control
A highly sophisticated piece of malware called AmnesiaStealer has been discovered targeting macOS users, using a novel approach to steal sensitive information. This malicious software not only collects passwords and cryptocurrency wallet data but also gives its operator real-time control over the victim’s web browser sessions. The implications are alarming, as this level of access allows attackers to navigate websites, export cookies, and even drive online portals with the victim’s existing authenticated sessions.
AmnesiaStealer is distributed via ClickFix campaigns that use fake GitHub download pages to drop a password-protected ZIP archive containing the malware. Once downloaded, the software captures the victim’s macOS password and uses it to collect keychain data, browser profiles, Apple Notes, Telegram sessions, documents, system information, and cryptocurrency wallet details. The malware also features a component called stream_module, which allows the operator to remotely control authenticated sessions deployed from a headless browser instance.
The stream_module works by duplicating user profiles in seven Chromium-based browsers, including Google Chrome, Microsoft Edge, Vivaldi, Arc, Opera, Brave, and Chromium. This is possible because these browsers share common protocols and encryption methods, making it easier for the malware to interact with them. The module then establishes a WebSocket channel that connects to the operator’s relay, allowing real-time control over the browser sessions.
One of the most concerning aspects of AmnesiaStealer is its ability to provide live remote control over the victim’s browser sessions. This means that attackers can not only steal sensitive information but also use it to navigate websites and perform malicious actions on behalf of the victim. According to researchers at Jamf, the operator receives a live screencast of the session at around 3 frames per second and can drive it with a full input set: keyboard, mouse, scroll, navigation, and tab management.
The AmnesiaStealer malware also contains a fallback mechanism that allows it to recover data even if the victim’s system is running macOS 26. This involves replacing an existing Chrome Safe Storage key with an attacker-supplied value, making previously stored cookies and passwords permanently unreadable while allowing the attacker to decrypt data later.
This level of sophistication in macOS malware highlights the need for users to remain vigilant and take proactive measures to protect their devices. AmnesiaStealer is a prime example of how attackers are constantly evolving their tactics to stay ahead of security defenses. To mitigate this risk, it’s essential for Mac users to keep their operating system and software up-to-date, use strong passwords, and be cautious when interacting with unfamiliar websites or downloading software. By being aware of these threats and taking steps to prevent them, we can all contribute to a safer online environment.
Source: Bleeping Computer — 2026-08-16