AmnesiaStealer Malware Targets macOS Users Through Browser Hijacking
AmnesiaStealer is a new malware targeting macOS users, capable of hijacking browser sessions through remote control. Developed via ClickFix attacks, it steals sensitive data and manipulates authenticated sessions.

A New Threat: Introducing AmnesiaStealer
A recent cybersecurity development has surfaced with the emergence of AmnesiaStealer, a new information-stealing malware specifically designed to target macOS users. This malware operates through ClickFix attacks, employing deceptive tactics to gain access to sensitive information and manipulate users' web browser sessions remotely.
The most alarming aspect of AmnesiaStealer is its capability to hijack authenticated browser sessions while masking its activities through a hidden, headless browser. By copying the victim's original browser profile, including saved credentials, the attackers can effectively replicate the victim's session, thus bypassing traditional security measures.
How AmnesiaStealer Operates
The malware is distributed via ClickFix campaigns that bait users into downloading a malicious, password-protected ZIP archive masquerading as a legitimate file from a fake GitHub page. Upon execution, it drops a Mach-O payload containing the malware. The ClickFix command executes a shell-script loader that facilitates this installation process. This loader gathers necessary credentials such as macOS passwords, allowing the malware to harvest keychain data, browser profiles, and various forms of sensitive information.
Exploitation Techniques
AmnesiaStealer incorporates a unique streaming module known as stream_module, which provides attackers with real-time, remote control over the victim's browser. Once the malware is executed, it utilizes a headless browser instance powered by the Chrome DevTools Protocol (CDP) to manage and redirect web activity. This method of operation is unprecedented in the macOS malware landscape, combining live session interactions with a cloned browser profile.
Targeted Browsers
| Browser Name | Browser Type |
|---|---|
| Google Chrome | Chromium-based |
| Microsoft Edge | Chromium-based |
| Vivaldi | Chromium-based |
| Arc | Chromium-based |
| Opera | Chromium-based |
| Brave | Chromium-based |
| Chromium | Chromium-based |
Impact on Security Standards
The use of seven different Chromium-based browsers allows AmnesiaStealer to duplicate user profiles, taking advantage of shared weaknesses in how these browsers operate. By leveraging the DevTools Protocol and employing command-line settings that disable crucial security defenses, the malware can extract extensive data, perform unauthorized commands, and create a live window into the victim’s online activities.
Data Types Hacked
| Data Type | Description |
|---|---|
| Passwords | Credentials stored in browsers and keychains |
| Cryptocurrency wallets | Details pertaining to users' digital currencies |
| Documents | Apple Notes and other local files |
| Session cookies | Cookies that maintain user authentication |
| Browsing history | Users’ online activities logged for personal use |
| Extensions | Browser extensions that might contain sensitive data |
| Telegrams | Messaging sessions that might contain sensitive content |

In-Depth Insights from Jamf Researchers
Research conducted by Jamf, a company specializing in Apple device management and security, reveals critical insights into the operations of AmnesiaStealer. They confirmed that this malware not only duplicates user profiles but also establishes two channels of communication with its command operator through WebSocket channels. This allows for both live monitoring and control of ongoing sessions, essentially transforming the infected device into a puppet controlled by the attacker.
Negative Consequences of Credential Theft
AmnesiaStealer's effectiveness is underscored by alarming statistics from the Blue Report 2026, which indicates that once attackers have valid credentials, defense mechanisms are only able to thwart 37% of their actions. This highlights the substantial risk associated with credential theft — even with existing security measures in place.
The report emphasizes that defense capabilities mask deeper operational failures post-initial access, as attacks exploit existing user credentials to bypass traditional security measures.
Recommendations for Users
To mitigate risks associated with AmnesiaStealer and similar threats, users are advised to:
- Educate themselves on the nature of ClickFix attacks and other social engineering methods.
- Refrain from executing commands in the terminal sourced online without complete understanding.
- Regularly update their macOS and browser software to ensure existing vulnerabilities are patched.
- Utilize strong, unique passwords for each service to minimize risks following credential breaches.
- Consider installing reputable security software that can detect and prevent unauthorized access.
Conclusion: Staying Vigilant Against Malware Threats
The emergence of AmnesiaStealer highlights the evolving strategies employed by cybercriminals to breach user security on macOS platforms. As threats become more sophisticated, users must prioritize their cybersecurity practices and remain vigilant against potential attack vectors.
Key Takeaways
- AmnesiaStealer can hijack browser sessions via a headless browser running on compromised systems.
- It targets 16 Chromium-based browsers, including Google Chrome and Microsoft Edge, to extract sensitive information.
- Jamf researchers warn that the malware uses a streaming module for remote control, allowing real-time browser manipulation.
- Credential theft is alarmingly effective, with only 37% of actions being blocked after valid credentials are acquired.
- Users should be cautious of ClickFix attacks and maintain robust defensive practices to protect against malware threats.
Frequently Asked Questions
