TechNewsReel
Live

AmnesiaStealer macOS Malware Hijacks Browser Sessions via Remote Control

A new Rust-based infostealer uses 'ClickFix' social engineering to gain live, interactive control over victims' authenticated browser sessions.

TechNewsReel Newsroom · August 16, 2026

A new Rust-based malware dubbed AmnesiaStealer is targeting macOS users by tricking them into granting attackers live, remote control over their web browsers. The threat leverages a sophisticated combination of social engineering and session hijacking to bypass traditional security boundaries.

Distributed through fake GitHub download pages, the malware employs "ClickFix" lures. These campaigns prompt users to resolve a fake technical error by pasting Base64-encoded commands directly into the macOS Terminal. Once executed, the malware establishes persistence via a root LaunchDaemon that impersonates Apple's own crash reporting service to avoid detection.

Beyond standard data theft, AmnesiaStealer features a specialized "stream_module." This component clones Chromium profiles and launches a headless browser instance using the Chrome DevTools Protocol (CDP). This allows attackers to maintain live, interactive control—including keyboard, mouse, and navigation inputs—at approximately 3 frames per second. While the malware targets 16 Chromium-based browsers for general data exfiltration, the remote control module specifically supports seven: Chrome, Brave, Edge, Arc, Opera, Vivaldi, and Chromium.

Deep System Access

The malware does not stop at the browser. It utilizes a spoofed system prompt to steal macOS system passwords. Once acquired, these credentials are used to unlock the iCloud Keychain and access sensitive local files, including PDFs, text documents, and digital wallets.

Why It Matters

This approach represents a significant escalation over traditional infostealers. Most malware simply dumps cookies and saved passwords for later use, which can be flagged by security systems when accessed from a different IP address or device. By operating a headless browser directly on the victim's machine, AmnesiaStealer preserves the host and network identifiers of the authenticated session.

By turning an infected host into a live, operator-driven browser, the malware provides a materially different level of access than simple file collection. This essentially transforms the victim's computer into a remote proxy for authenticated access to secure online portals, bypassing many multi-factor authentication (MFA) or IP-based security checks.

The Broader Threat

AmnesiaStealer is part of a growing trend of "ClickFix" attacks and shares distribution templates with other macOS threats like Atomic and MacSync. The malware is linked to the "Amnesia Panel" C2 backend, which contains Russian-language error messages. Security researchers continue to monitor the evolution of these Rust-based stealers as they move toward real-time session manipulation rather than static data theft, signaling a shift in how attackers maintain persistence and access within hardened environments.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.