Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    New AmnesiaStealer macOS malware hijacks browser sessions via remote control

    August 16, 2026

    お家時間に最適な物達をプレゼンしました

    August 15, 2026

    AI ‘watermark removers’ flood the web. Almost none can prove they work.

    August 15, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»New AmnesiaStealer macOS malware hijacks browser sessions via remote control
    News

    New AmnesiaStealer macOS malware hijacks browser sessions via remote control

    adminBy adminAugust 16, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    New AmnesiaStealer macOS malware hijacks browser sessions via remote control

    A new information-stealing malware called AmnesiaStealer, which targets macOS users via ClickFix attacks, includes a streaming module that allows the attacker to interactively control the victim’s web browser.

    A notable capability is copying the victim’s Chromium profile, including its authentication state, and loading it into a hidden, headless browser on the infected system.

    This allows the hacker to access victims’ authenticated sessions while preserving the identifiers associated with the browser, host, and network.

    image

    AmnesiaStealer can collect data in 16 Chromium-based web browsers as well as other sensitive information, such as passwords, cryptocurrency wallets, Apple Notes and documents, and keychain data.

    The malware is currently distributed through ClickFix campaigns that use a fake GitHub download page to drop a password-protected ZIP archive.

    The fake GitHub page pushing a ClickFix lure
    Fake GitHub page pushing a ClickFix lure
    Source: Jamf

    Researchers at Jamf, an Apple device management and security company, analyzed AmnesiaStealer’s distribution and found that it used the same template previously used to spread the Atomic and MacSync infostealers.

    The ClickFix command executes a shell-script loader that downloads and launches the password-protected archive containing the AmnesiaStealer Mach-O payload.

    The malware captures the victim’s macOS password and uses it to collect keychain data, as well as browser profiles, Apple Notes, Telegram sessions, documents, system information, and cryptocurrency wallet data.

    Stealing the admin password
    Stealing the admin password
    Source: Jamf

    The researchers highlight that the malware features a component called stream_module, retrieved using the remote_stream command, which gives the malicious operator remote control over authenticated sessions deployed from a headless browser instance.

    According to Jamf, AmnesiaStealer’s stream_module can duplicate user profiles in seven Chromium-based browsers, including Google Chrome, Microsoft Edge, Vivaldi, Arc, Opera, Brave, and Chromium, because they share the same DevTools Protocol, launch flags, and cookie encryption.

    The module launches the legitimate browser executable in headless mode with command-line switches that weaken browser defenses, duplicates the victim’s profile, and specifies its location for storing the profile data.

    The malware then establishes a WebSocket channel that connects to the operator’s relay and sends a JSON registration message containing the browser name and build.

    The operator can then send commands over this channel, such as navigation and mouse clicks, while the malware returns status and tab information as JSON and transmits screencast frames as binary WebSocket messages.

    A second WebSocket channel connects to the local headless Chromium instance through the browser’s webSocketDebuggerUrl, providing access to the Chrome DevTools Protocol (CDP).

    This allows the hacker to navigate websites with mouse and keyboard control, export or import cookies, and operate online portals using the victim’s existing authenticated sessions.

    “The operator receives a live screencast of the session at around 3fps and can drive it with a full input set: keyboard, mouse, scroll, navigation and tab management,” Jamf explains.

    “In effect the remote_stream command turns an infected host into a live, operator-driven browser running the victim’s authenticated sessions, which is a materially different level of access from file collection.”

    From the live screencast
    From the live screencast
    Source: Jamf

    According to the researchers, the AmnesiaStealer can exfiltrate cookies, saved logins, browsing history, bookmarks, extensions, local state, and other profile data from the 16 Chromium-based browsers it targets.

    It also steals cryptocurrency wallet details and identifies them by enumerating extensions and IndexedDB data.

    Jamf notes that the malware contains a fallback mechanism when it runs on macOS 26 and cannot recover the existing Chrome Safe Storage key, which replaced it with an attacker-supplied value.

    This makes previously stored cookies and passwords permanently unreadable while allowing the attacker to decrypt data later.

    The Chrome DevTools Protocol (CDP) has been abused by malware in the past, including by Chaos ransomware to hide command-and-control communications, and by Chaes malware to expose browser functions that could enable data theft.

    However, AmnesiaStealer appears to be the first documented macOS malware to combine a cloned Chromium profile with CDP-based, live remote control, allowing attackers to interact with authenticated sessions through a hidden browser running on the infected computer.

    Users are advised never to execute commands in the terminal that they found online and don’t fully understand.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous Articleお家時間に最適な物達をプレゼンしました
    admin
    • Website

    Related Posts

    News

    AI ‘watermark removers’ flood the web. Almost none can prove they work.

    August 15, 2026
    News

    Microsoft patches LegacyHive Windows zero-day vulnerability

    August 15, 2026
    News

    Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt

    August 15, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views
    Our Picks

    New AmnesiaStealer macOS malware hijacks browser sessions via remote control

    August 16, 2026

    お家時間に最適な物達をプレゼンしました

    August 15, 2026

    AI ‘watermark removers’ flood the web. Almost none can prove they work.

    August 15, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.