Close Menu
NCIJ Network NCIJ Network
    What's Hot

    The influencers getting bitten chasing the perfect shark shot

    August 16, 2026

    Poll: Democrat David Crowley opens fall gubernatorial campaign with slight edge over Republican Tom Tiffany 

    August 16, 2026

    Teenager arrested after five shot at Virginia State University

    August 16, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The influencers getting bitten chasing the perfect shark shot
    • Poll: Democrat David Crowley opens fall gubernatorial campaign with slight edge over Republican Tom Tiffany 
    • Teenager arrested after five shot at Virginia State University
    • Four ‘extraordinary’ Renaissance paintings stolen from Italian museum
    • A positive new report raises the question: was Reeves undermined by dodgy data? | Heather Stewart
    • Calls for public inquiry into Jason Arday media ‘witchhunt’
    • Rogue AI aren’t science fiction anymore
    • New AmnesiaStealer macOS malware hijacks browser sessions via remote control
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Sunday, August 16
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    New AmnesiaStealer macOS malware hijacks browser sessions via remote control

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 16, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A new information-stealing malware called AmnesiaStealer, which targets macOS users via ClickFix attacks, includes a streaming module that allows the attacker to interactively control the victim’s web browser.

    A notable capability is copying the victim’s Chromium profile, including its authentication state, and loading it into a hidden, headless browser on the infected system.

    This allows the hacker to access victims’ authenticated sessions while preserving the identifiers associated with the browser, host, and network.

    image

    AmnesiaStealer can collect data in 16 Chromium-based web browsers as well as other sensitive information, such as passwords, cryptocurrency wallets, Apple Notes and documents, and keychain data.

    The malware is currently distributed through ClickFix campaigns that use a fake GitHub download page to drop a password-protected ZIP archive.

    The fake GitHub page pushing a ClickFix lure
    Fake GitHub page pushing a ClickFix lure
    Source: Jamf

    Researchers at Jamf, an Apple device management and security company, analyzed AmnesiaStealer’s distribution and found that it used the same template previously used to spread the Atomic and MacSync infostealers.

    The ClickFix command executes a shell-script loader that downloads and launches the password-protected archive containing the AmnesiaStealer Mach-O payload.

    The malware captures the victim’s macOS password and uses it to collect keychain data, as well as browser profiles, Apple Notes, Telegram sessions, documents, system information, and cryptocurrency wallet data.

    Stealing the admin password
    Stealing the admin password
    Source: Jamf

    The researchers highlight that the malware features a component called stream_module, retrieved using the remote_stream command, which gives the malicious operator remote control over authenticated sessions deployed from a headless browser instance.

    According to Jamf, AmnesiaStealer’s stream_module can duplicate user profiles in seven Chromium-based browsers, including Google Chrome, Microsoft Edge, Vivaldi, Arc, Opera, Brave, and Chromium, because they share the same DevTools Protocol, launch flags, and cookie encryption.

    The module launches the legitimate browser executable in headless mode with command-line switches that weaken browser defenses, duplicates the victim’s profile, and specifies its location for storing the profile data.

    The malware then establishes a WebSocket channel that connects to the operator’s relay and sends a JSON registration message containing the browser name and build.

    The operator can then send commands over this channel, such as navigation and mouse clicks, while the malware returns status and tab information as JSON and transmits screencast frames as binary WebSocket messages.

    A second WebSocket channel connects to the local headless Chromium instance through the browser’s webSocketDebuggerUrl, providing access to the Chrome DevTools Protocol (CDP).

    This allows the hacker to navigate websites with mouse and keyboard control, export or import cookies, and operate online portals using the victim’s existing authenticated sessions.

    “The operator receives a live screencast of the session at around 3fps and can drive it with a full input set: keyboard, mouse, scroll, navigation and tab management,” Jamf explains.

    “In effect the remote_stream command turns an infected host into a live, operator-driven browser running the victim’s authenticated sessions, which is a materially different level of access from file collection.”

    From the live screencast
    From the live screencast
    Source: Jamf

    According to the researchers, the AmnesiaStealer can exfiltrate cookies, saved logins, browsing history, bookmarks, extensions, local state, and other profile data from the 16 Chromium-based browsers it targets.

    It also steals cryptocurrency wallet details and identifies them by enumerating extensions and IndexedDB data.

    Jamf notes that the malware contains a fallback mechanism when it runs on macOS 26 and cannot recover the existing Chrome Safe Storage key, which replaced it with an attacker-supplied value.

    This makes previously stored cookies and passwords permanently unreadable while allowing the attacker to decrypt data later.

    The Chrome DevTools Protocol (CDP) has been abused by malware in the past, including by Chaos ransomware to hide command-and-control communications, and by Chaes malware to expose browser functions that could enable data theft.

    However, AmnesiaStealer appears to be the first documented macOS malware to combine a cloned Chromium profile with CDP-based, live remote control, allowing attackers to interact with authenticated sessions through a hidden browser running on the infected computer.

    Users are advised never to execute commands in the terminal that they found online and don’t fully understand.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    AmnesiaStealer browser control Hijacks macOS Malware remote Sessions
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    New Evooo1Bot Linux botnet turns routers into traffic relay nodes

    AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions

    Hackers Exploiting Unpatched GeoServer Zero-Day

    Critical VMware vCenter RCE flaw exploited for reverse SSH access

    RingCentral data breach exposed info of 1.6 million accounts

    14,000 Trezor Customers Impacted by Data Breach at ShipMonk

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    The influencers getting bitten chasing the perfect shark shot

    August 16, 2026

    Poll: Democrat David Crowley opens fall gubernatorial campaign with slight edge over Republican Tom Tiffany 

    August 16, 2026

    Teenager arrested after five shot at Virginia State University

    August 16, 2026

    Four ‘extraordinary’ Renaissance paintings stolen from Italian museum

    August 16, 2026
    Latest Posts

    Heathrow expansion would take thousands of jobs from other UK regions, report finds | Heathrow third runway

    July 27, 2026

    Farage’s latest gamble clouds Reform’s path to power – POLITICO

    July 27, 2026

    Pauline Hanson loses bid to overturn Mehreen Faruqi racial discrimination finding | Australian Greens

    July 27, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    The influencers getting bitten chasing the perfect shark shot

    August 16, 2026

    Poll: Democrat David Crowley opens fall gubernatorial campaign with slight edge over Republican Tom Tiffany 

    August 16, 2026

    Teenager arrested after five shot at Virginia State University

    August 16, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.