AmnesiaStealer macOS Malware Hijacks Browser Sessions Through ClickFix Attacks
A newly identified macOS information-stealing malware known as AmnesiaStealer is being distributed through ClickFix attacks and includes a remote browser-control feature that allows cybercriminals to interact with victims’ authenticated web sessions.
The malware copies a victim’s Chromium browser profile, including its authentication data, and loads the profile into a hidden headless browser running on the compromised Mac.
By doing so, attackers can access websites through the victim’s existing authenticated session while preserving browser, device, and network identifiers that may help the activity appear legitimate.
AmnesiaStealer can target data from 16 Chromium-based browsers. Its information-stealing capabilities also include the collection of passwords, cryptocurrency wallets, Apple Notes, documents, Telegram sessions, and macOS Keychain data.
Researchers say the malware is currently spread through a ClickFix campaign that uses fake GitHub download pages to trick users into downloading password-protected ZIP archives.

Source: Jamf
Jamf, an Apple device management and security company, analyzed the AmnesiaStealer campaign and found that it used a distribution template previously associated with the Atomic and MacSync macOS infostealers.
The ClickFix payload executes a shell-script loader that downloads and launches a password-protected archive containing the AmnesiaStealer Mach-O malware.
After execution, the malware attempts to capture the user’s macOS password. It then uses that information to access Keychain data, browser profiles, Apple Notes, Telegram sessions, documents, system details, and cryptocurrency wallet information.

Source: Jamf
One of the malware’s most notable components is called stream_module. Delivered through the remote_stream command, the module enables attackers to remotely control authenticated browser sessions running inside hidden headless browser instances.
According to Jamf, the stream_module can replicate profiles from seven Chromium-based browsers, including Google Chrome, Microsoft Edge, Vivaldi, Arc, Opera, Brave, and Chromium. These browsers use compatible DevTools protocols, launch options, and cookie-encryption mechanisms.
The malware launches a legitimate browser executable in headless mode with command-line options that weaken certain browser protections. It then clones the victim’s profile and specifies a location for storing the copied profile data.
AmnesiaStealer establishes a WebSocket connection to an attacker-controlled relay and sends a JSON registration message containing information such as the browser name and version.
Through this connection, the operator can issue commands for actions including web navigation and mouse clicks. The malware returns browser status and tab information in JSON format while transmitting screencast frames as binary WebSocket messages.
A second WebSocket connection links the malware to the local headless Chromium instance through its webSocketDebuggerUrl. This gives the attacker access to the Chrome DevTools Protocol, also known as CDP.
Using CDP, attackers can navigate websites, control the mouse and keyboard, export or import cookies, and interact with online services through the victim’s existing authenticated session.
“Operators receive a live screencast of the session at approximately 3fps and can interact with it using a full set of inputs including keyboard, mouse, scrolling, navigation, and tab management,” Jamf explains.
“Effectively, the remote_stream command turns the infected host into a live, operator-driven browser that runs the victim’s authenticated session. This is a substantially different level of access than file harvesting.”

Source: Jamf
In addition to its remote browser-control capabilities, AmnesiaStealer can steal cookies, saved login credentials, browsing history, bookmarks, browser extensions, local-state files, and other profile data from 16 Chromium-based browsers.
The malware also searches for cryptocurrency wallet information by examining browser extensions and IndexedDB data, where some wallet applications store account-related information.
Jamf reports that AmnesiaStealer includes a fallback mechanism for macOS 26. The mechanism addresses situations in which existing Chrome Safe Storage keys have been replaced with attacker-controlled values.
As a result, previously stored cookies and passwords may become permanently unreadable to the legitimate user while remaining decryptable by the attacker at a later stage.
Cybercriminals have previously abused the Chrome DevTools Protocol. For example, Chaos ransomware used CDP to conceal command-and-control traffic, while Chaes malware exploited browser functionality to facilitate data theft.
However, AmnesiaStealer appears to be the first documented macOS malware family to combine a cloned Chromium profile with CDP-based, live remote browser control. This approach allows attackers to operate an authenticated session through a hidden browser on the infected Mac.
Mac users should avoid copying and running terminal commands found online unless they fully understand what the commands do. Users should also be cautious of fake GitHub download pages, unexpected ZIP archives, and ClickFix prompts that instruct them to paste commands into Terminal.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




