Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Kimsuky Uses AI-Generated Chrome Extension to Steal Gmail Data
August 24, 2026
768 Leaked Corporate AWS Keys Grant Full Administrator Access
August 24, 2026
ReliaQuest Warns of Phishing Attacks Impersonating Staff for SSO Credentials
August 24, 2026
Home/CyberSecurity News/AmnesiaStealer malware grants attackers hidden control of Mac browsers
CyberSecurity News

AmnesiaStealer malware grants attackers hidden control of Mac browsers

Key Takeaways A new macOS info-stealing malware, AmnesiaStealer, offers attackers live control of compromised web browsers. The malware bypasses multi-factor authentication by hijacking active,...

Sarah simpson
Sarah simpson
August 24, 2026 4 Min Read
3 0

Key Takeaways

  • A new macOS info-stealing malware, AmnesiaStealer, offers attackers live control of compromised web browsers.
  • The malware bypasses multi-factor authentication by hijacking active, authenticated browser sessions.
  • It is distributed via a social engineering technique called ClickFix, which tricks users into executing malicious Terminal commands.
  • AmnesiaStealer targets credentials, browser data, Apple Notes, Telegram sessions, documents, cryptocurrency wallets, and keychain information.
  • The threat establishes persistence through a disguised LaunchDaemon, making a one-time execution a long-term compromise.

Cybersecurity researchers have uncovered a sophisticated macOS information stealer, dubbed AmnesiaStealer, that goes beyond typical credential theft. This new malware empowers attackers with silent, real-time control over authenticated browser sessions on infected Mac systems, effectively turning a victim’s machine into an undetected conduit to sensitive accounts like email, business applications, and cryptocurrency services.

Table Of Content

  • Key Takeaways
  • AmnesiaStealer’s Covert Browser Control
  • ClickFix Lure Elevates Risk

The distribution of AmnesiaStealer leverages a social engineering tactic known as ClickFix. This method manipulates users into voluntarily executing a command. Victims are directed to deceptive GitHub download pages, where they are instructed to copy and paste a specific command into their Terminal application. This command then initiates the download and execution of a multi-stage, Rust-based payload, while simultaneously removing any traces of the installation to evade detection.

According to a Polyswarm report, the malware is designed to harvest a broad spectrum of sensitive data. This includes login credentials, comprehensive browser records, Apple Notes, Telegram session data, various documents, browser-related cryptocurrency wallet information, and material from the macOS keychain. Analysts at Polyswarm highlight this as a significant evolution in malware capabilities, moving from mere data exfiltration to active, interactive exploitation of authenticated browser sessions.

The danger posed by AmnesiaStealer is particularly severe because it can bypass multi-factor authentication (MFA). While a stolen password can often be reset, an active browser session already satisfies MFA requirements, granting attackers immediate access without further prompts. Furthermore, the malware establishes a stealthy LaunchDaemon for persistence, ensuring that a single, ill-advised Terminal command can lead to a prolonged compromise of the system.

AmnesiaStealer’s Covert Browser Control

The defining characteristic of AmnesiaStealer is its advanced second-stage browser streaming module. Following an initial data collection phase, threat actors can activate a component that duplicates the victim’s browser profile and initiates it within a hidden, headless Chromium session. Crucially, the user’s visible browser remains operational, often displaying no signs of malicious activity.

This module communicates via the legitimate Chrome DevTools Protocol, typically used for debugging purposes. In the hands of an attacker, this protocol grants full control, enabling them to navigate websites, manage tabs, simulate keyboard and mouse inputs, and observe browser output in real time. The malware supports seven different Chromium-family browsers.

This level of access fundamentally alters the value of an infection. Instead of sifting through exfiltrated data post-breach, attackers can directly interact with live, authenticated sessions. This allows them to view account pages, complete sign-in processes, export decrypted cookies, or even import cookies into a separate session. This mirrors the broader threat seen in macOS credential theft, where stolen browser data facilitates comprehensive account takeover.

The initial stage of AmnesiaStealer targets sixteen Chromium-based browsers, meticulously gathering cookies, login databases, browsing history, bookmarks, extensions, local state data, preferences, and other associated artifacts. It also attempts to retrieve each browser’s Safe Storage key from the login keychain, which could aid the subsequent module in decrypting and accessing protected browser information.

AmnesiaStealer is designed for adaptability, with its operation varying based on the specific campaign and macOS version. Researchers have observed encrypted, build-specific settings and execution paths, along with attempts to bypass older privacy controls that Apple has already patched. This inherent flexibility means that behavioral indicators, rather than static file signatures, are crucial for effective detection by defenders.

ClickFix Lure Elevates Risk

The initial infection vector for AmnesiaStealer bypasses software vulnerabilities, instead relying on social engineering to exploit user trust. A convincing, fake download page mimics legitimate developer sites, replacing standard installation procedures with instructions to execute Terminal commands. Previous macOS ClickFix attack reports illustrate how attackers exploit common verification or download prompts to trick users into self-installing malware.

Upon execution, AmnesiaStealer first profiles the Mac system and then displays an Installer-themed prompt, requesting the user’s password. It validates this password locally, unlocks the login keychain, bundles all stolen data, and transmits it to attacker-controlled infrastructure. Following this, it establishes its persistence mechanism and meticulously deletes any forensic artifacts.

Users should be extremely wary of any webpage, regardless of its apparent legitimacy (e.g., GitHub, CAPTCHA, or support pages), that instructs them to paste commands into Terminal. Recent <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/21a81b4e-f3ac-43aa-86e4-2e5cc35b04b5/AmnesiaStealer-Gives-Hackers-Hidden-Control-of-Logged-In-Browsers-on-Macs.pdf?AWSAccessKeyId=ASIA2F3EMEYEYJOHNHCQ&Signature=XFEQ%2B1jSLaIOumELXlIwPhI34HA%3D&x-amz-security-token=IQoJb3JpZ2luX2VjECIaCXVzLWVhc3QtMSJHMEUCICo97aE0YXWdogdYRNkcjRkHf3AXH3UvEjJqmv%2BJB6YqAiEA5pAO0E16XyCGaJQCp2Zy2HjwlXvbwSEHM7YsqkPuHGMq%2FAQI6%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDBo%2B8hx9Z754GqNVdSrQBHF9q%2BtVxXRtF%2BMxRyUJIWkeI1cpRsBVrv3Htrc0MNfDR7pqd0pluai3ocdzAFO8NVe4Aq7W6nAvCdl97WxGzE5wbSLp8cQCgcAKiP%2B3LOFBs6IpiXkiSSs%2BFF28L4RHarxVZ0vlIrXnZjIIpAEukudWpNB31DCXHl7fJiSzvYtov1252WOTHZ8tOz6Fh%2FicjTHeWrH4W7YWttqDRTwKOOHtp3NymsfMNKUuhWvjKsvEXOkVotjjl%2F9GG48OVrEcQmyAxCtAI02haEqNSPn0RquQTbPIBnu8V6VRMD6S8uXH8tR29ihuwrj9kx9wFOYs%2FZBFABFp8%2FrrFq3F8oL9nEmDkf8q8Tv3S1CGZ6vechnVk75KdB0XMoKKEHgjnIS1RYWEc7AzE5405C2lhSLU70ve6MGnRsix6PIYDXgF7AfyHRK9NGhm8lQp4zuDF%2FG%2FWRtiz%2Fe5vzO1NFy38sI4QdeQY0TxovM5qQg3rgLf7RKr845R%2FLpeiVqEy6QYwIE4i0x2%2BTHjNL1ZTKnOIvSnNYU90ixGHeV7GkxQtmLxoWtouEyqRRwpmlwQCeoS6Z%2F11c4aHgFLlU8SnfqwvjqvNr6hDCUe2eozPRCXqKC%2B2tQBGoevSP3g%2Fad%2BeTf3QeM189pEmCUNKWdZXfkeplGiWvdgqL4F65PBHF4WKjKoo4B1GEGujMougjz%2BUoac67GEgmIcisS7Y%2FvfCjCIQ%2BFY1sXCSPaPKeqVkCEVx5RFyC8Vi%2BNbQV2IG

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwareSecurityThreatVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Critical Vulnerabilities in Harman Kardon Infotainment Systems Expose Android Car Screens

Next Post

New Mac Backdoor Masquerades as CAPTCHA, Steals Passwords, Mines Crypto

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical WordPress Plugin Vulnerability Exposes 100,000 Sites
August 24, 2026
New Mac Backdoor Masquerades as CAPTCHA, Steals Passwords, Mines Crypto
August 24, 2026
AmnesiaStealer malware grants attackers hidden control of Mac browsers
August 24, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us