AmnesiaStealer macOS Malware Hijacks Browser Sessions via Remote Control

www.news4hackers.com-amnesiastealer-macos-malware-hijacks-browser-sessions-via-remote-control-amnesiastealer-macos-malware-hijacks-browser-sessions-via-remote-control

A recently identified information-stealing malware targeting macOS systems, designated AmnesiaStealer, employs ClickFix attack vectors to compromise user devices.

Overview of AmnesiaStealer

AmnesiaStealer is a macOS malware that enables remote manipulation of web browser sessions through interactive control mechanisms. It includes a streaming module that grants attackers real-time access to victims’ web browsing activities. The malware’s core functionality involves extracting Chromium-based browser profiles, including authentication states, and integrating them into a concealed, headless browser environment on the infected machine.

ClickFix Attack Vectors

The malware’s distribution occurs through ClickFix campaigns that utilize deceptive GitHub pages to deliver malicious payloads. Researchers at Jamf, an Apple device security and management firm, discovered that AmnesiaStealer leverages a distribution template previously associated with Atomic and MacSync infostealers.

“The ClickFix command initiates a shell-script loader that captures the victim’s macOS password to access keychain data, browser profiles, Apple Notes, Telegram sessions, system information, and cryptocurrency wallet details,” said Jamf.

Key Features and Capabilities

AmnesiaStealer is capable of harvesting data from 16 Chromium-compatible web browsers alongside sensitive information such as login credentials, cryptocurrency wallet details, Apple Notes, documents, and keychain data. The malware’s stream_module component, activated via the remote_stream command, provides attackers with remote control over authenticated sessions through a headless browser instance.

Browser Profile Cloning and Remote Control

The module can replicate user profiles in seven Chromium-based browsers—Google Chrome, Microsoft Edge, Vivaldi, Arc, Opera, Brave, and Chromium—due to shared DevTools Protocol implementations, launch flags, and cookie encryption methods. It executes the legitimate browser executable in headless mode with modified command-line switches that weaken security protections.

Data Exfiltration and Fallback Mechanism

AmnesiaStealer can exfiltrate cookies, saved login credentials, browsing history, bookmarks, extensions, local state, and other profile data from the 16 targeted Chromium-based browsers. It also identifies cryptocurrency wallet information by analyzing extensions and IndexedDB data. A fallback mechanism for macOS 26 systems replaces the Chrome Safe Storage key with an attacker-supplied value, rendering previously stored data inaccessible.

Threat Landscape and Mitigation

The malware represents the first documented macOS malware to combine cloned Chromium profiles with CDP-based live remote control, allowing attackers to interact with authenticated sessions through a hidden browser on the infected device. Security professionals advise against executing terminal commands from untrusted sources without thorough understanding.

Research indicates that only 37% of attacker actions are blocked once valid credentials are obtained. Additional coverage includes emerging threats such as CrashStealer, ClickLock malware, and macOS Screen Sharing vulnerabilities. Other reports highlight ClickFix campaigns distributing macOS infostealers for cryptocurrency theft and fake Roblox Xeno script launchers delivering infostealer and RAT malware.

Conclusion

AmnesiaStealer poses a significant threat to macOS users, leveraging advanced techniques to maintain persistent access to authenticated sessions. Comprehensive threat intelligence reports and updated mitigation strategies are essential for defending against such sophisticated attacks.

FAQs

What is AmnesiaStealer? AmnesiaStealer is a macOS malware that enables remote manipulation of web browser sessions through interactive control mechanisms, targeting Chromium-based browsers and sensitive user data.

How does AmnesiaStealer distribute? It uses ClickFix campaigns with deceptive GitHub pages to deliver malicious payloads, leveraging a distribution template linked to previous infostealers like Atomic and MacSync.

What data does AmnesiaStealer steal? It steals login credentials, cryptocurrency wallet details, Apple Notes, documents, keychain data, and browser profiles, including cookies and browsing history.

How can users protect themselves? Avoid executing terminal commands from untrusted sources, stay informed about threat intelligence reports, and implement robust security measures to block attacker actions after credential compromise.



About Author

en_USEnglish