AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions

A New macOS Malware Threat: AmnesiaStealer Steals Data and Takes Control of Browser Sessions

A sophisticated piece of malware has been discovered targeting macOS users, with alarming capabilities that allow attackers to steal sensitive data and even control browser sessions. Dubbed AmnesiaStealer, this multi-stage threat is being spread through fake GitHub download pages in recent ClickFix attacks.

AmnesiaStealer works by executing a shell script, which fetches and runs the malware’s payload. The infostealer then harvests data from the victim’s system, including login credentials, data-protection keychains, and browser databases. It also attempts to bypass security controls using patched macOS exploits and arches the stolen data for transmission to its command-and-control server.

But that’s not all – AmnesiaStealer has a particularly insidious feature: it can take control of the victim’s browser session. By receiving a remote_stream command, the malware downloads and runs a stream module that clones the browser profile and launches it headless, providing attackers with full access to the victim’s browsing activities.

The malware specifically targets six Chromium-based browsers, including Chrome, Brave, Arc, and Edge, by overwriting the per-browser Safe Storage key in the login keychain. This means that previously saved passwords and cookies are rendered unrecoverable. To steal Safari cookies and access the Transparency, Consent, and Control framework database, AmnesiaStealer uses an old vulnerability (CVE-2020-9771) – but only on macOS 26 systems.

In a chilling demonstration of its capabilities, Jamf notes that the final stream module allows attackers to receive a live screencast of the browser session at around 3 frames per second and drive it with a full input set: keyboard, mouse, scroll, navigation, and tab management. This translates into real-time CDP calls against the headless browser.

The implications are clear: AmnesiaStealer is a highly sophisticated threat that allows attackers to not only steal sensitive data but also gain control over victims’ browsing activities. Users must be vigilant about suspicious download pages and beware of command-line prompts that may lead to malware installation. It’s essential to keep operating systems up-to-date, use robust security software, and exercise caution when interacting with unknown websites.

To protect yourself from AmnesiaStealer and similar threats, consider implementing the following best practices:

* Regularly update your operating system and applications

* Use reputable antivirus software and a firewall

* Avoid suspicious download pages and command-line prompts

* Use strong, unique passwords for all accounts

* Consider using two-factor authentication (2FA) whenever possible

By taking these precautions, you can significantly reduce the risk of falling victim to AmnesiaStealer or other malware threats. Stay informed, stay vigilant – and protect your digital assets from this emerging threat.


Source: SecurityWeek — 2026-08-14