Apple Mac Malware Lets Attackers Control Browser Sessions After Infection

Apple Mac Malware Lets Attackers Control Browser Sessions After Infection

Apple Macs are being targeted by AmnesiaStealer, an infostealer that can give attackers access to active browser sessions. Source: Wes Hicks/Unsplash

AmnesiaStealer malware targets macOS with data theft and remote browser-session control, potentially exposing accounts already open on compromised Macs.

Écrit par
Liz Ticong
Liz Ticong
Aug 17, 2026
We may earn from vendors via affiliate links or sponsorships. This might affect product placement on our site, but not the content of our reviews. See our Terms of Use for details.

A routine-looking download can turn into a much bigger problem for Mac users.

Jamf Threat Labs found an AmnesiaStealer campaign reaching macOS through a fake software download and capable of keeping attackers connected to browser sessions after infection. Researchers say the added access can extend the intrusion beyond the malware’s initial data theft.

An attack begins with a user-run Terminal command, but its more unusual stage comes later, after AmnesiaStealer is already inside the system.

A fake download opens the door on macOS

Jamf Threat Labs traced the campaign to a counterfeit GitHub-style page offering a macOS download. Visitors are instructed to copy an encoded command into Terminal, using a ClickFix attack chain that relies on the target to execute the malicious instructions.

Running the command triggers a shell script that downloads and launches AmnesiaStealer. The malware also attempts to obtain the user’s login password as it prepares to collect information from the system.

Turning stolen data into browser access

AmnesiaStealer first collects information stored on the infected device. Jamf found it targeting browser data and the macOS Keychain, with Apple Notes and Telegram also in its sights.

Mac infostealers have pursued similar information before. FrigidStealer, for example, has targeted browser credentials and Apple Notes.

The malware can then download an optional component called stream_module. This can copy a Chromium browser profile and launch another browser instance outside the user’s view. Operators can see what appears in the browser and send keyboard or mouse input back to it.

Copied browser data can preserve an authenticated session. Services that still recognize an existing session may not immediately ask for another login. Stolen session cookies can create a similar problem, while remote browser control also allows an operator to interact with the session from the compromised system.

Advertisement

Must-read Apple coverage

Work accounts raise the cost of a compromised device

If you use a Mac for work, treat a suspected AmnesiaStealer infection as more than a malware-removal job. Accounts already open in the browser may include company email or cloud services, depending on your role and access.

Take the affected device offline and contact your IT or security team if it is company-managed. Use a clean device to revoke active sessions and reset passwords for sensitive accounts. Review recent activity for anything you do not recognize.

If your role includes privileged or financial access, tell responders which services were open or recently used. A session tied to an administrative console or finance platform can carry permissions well beyond an ordinary user account.

Credential recovery should run alongside endpoint investigation. Unexpected Chromium processes or copied browser profiles can help establish whether the browser-control component was used. Recent threats such as ClickLock malware have already made credential theft a concern for Apple users, and AmnesiaStealer adds another form of access for defenders to account for after an infection.

Other News: WhatsApp is testing on-device AI scam alerts that flag suspicious messages from unknown senders without sending message content to the cloud.

Liz Ticong

Liz Ticong is a technology writer specializing in artificial intelligence, cybersecurity, software reviews, and emerging business technologies. With more than a decade of professional writing experience and over five years contributing technology content for TechnologyAdvice, she helps readers understand complex technologies and evaluate the tools that best fit their needs. Liz has extensive experience researching, testing, and analyzing software platforms, AI tools, and technology solutions. Her work includes in-depth software reviews, buyer’s guides, product comparisons, and technology news coverage designed to help businesses make informed purchasing and implementation decisions. She regularly evaluates AI applications, automation tools, cybersecurity solutions, and business software, providing practical insights based on hands-on testing and research. In addition to her work with TechnologyAdvice, Liz has contributed technology content to leading industry publications, including eWeek and TechRepublic. Her background in technical writing and software analysis enables her to translate complex technical concepts into clear, actionable guidance for both business and technology audiences. Liz holds a bachelor's degree in Broadcast Communication from the Polytechnic University of the Philippines and continues to expand her expertise through ongoing education in artificial intelligence and emerging technologies. Through her writing, she helps readers navigate a rapidly evolving technology landscape with practical, research-driven insights and real-world product analysis.