CVE Tools
Back to feed
Research macOS malware Chromium-based browsers Google phishing

AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS

The Hacker News·By The Hacker News··5 min read
CVE Tools coverage

Jamf Threat Labs identified a new Rust-based macOS information stealer named AmnesiaStealer that combines credential harvesting with the ability to remotely operate Chromium-based browsers such as Google Chrome and Microsoft Edge. Distributed through fraudulent GitHub download pages using ClickFix techniques, the malware extracts system passwords, Keychain data, and browser sessions to exfiltrate sensitive user information. Distinctively, it utilizes the Chrome DevTools Protocol to launch headless browsers, allowing operators to manipulate tabs, input keystrokes, and navigate sites in real-time while spoofing fingerprinting checks.
The tool leverages patched vulnerabilities like CVE-2020-9771 to access protected data on older macOS versions, establishing persistence through disguised system services. While no specific threat actor attribution was provided, the combination of automated data theft and interactive session hijacking represents a significant escalation in macOS malware capabilities.