AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS
ResearchmacOSChromium-based browsersOur summary
Jamf Threat Labs identified a new Rust-based macOS information stealer named AmnesiaStealer that combines credential harvesting with the ability to remotely operate Chromium-based browsers such as Google Chrome and Microsoft Edge. Distributed through fraudulent GitHub download pages using ClickFix techniques, the malware extracts system passwords, Keychain data, and browser sessions to exfiltrate sensitive user information. Distinctively, it utilizes the Chrome DevTools Protocol to launch headless browsers, allowing operators to manipulate tabs, input keystrokes, and navigate sites in real-time while spoofing fingerprinting checks.
The tool leverages patched vulnerabilities like CVE-2020-9771 to access protected data on older macOS versions, establishing persistence through disguised system services. While no specific threat actor attribution was provided, the combination of automated data theft and interactive session hijacking represents a significant escalation in macOS malware capabilities.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.