A new malware called AmnesiaStealer targets macOS users to hijack browser sessions through a remote-control streaming module [1, 2, 3].

This development is significant because it allows attackers to interactively control a victim's web browser in real time. By gaining live access, hackers can bypass traditional security measures to steal cookies, and sensitive session tokens [1, 2, 3].

Security researchers found that the malware spreads via "ClickFix" lures [1, 3]. These lures typically trick users into performing a specific action that triggers the infection on their macOS devices [1]. Once the system is compromised, the malware targets Chromium-based browsers [2, 3].

A key feature of AmnesiaStealer is its ability to stream a remote-control module to the infected machine [1]. This functionality enables the attacker to interact with the browser as if they were the local user [1]. The Hacker News said the malware gives attackers live Chromium control via the Chrome DevTools Protocol (CDP) [2].

By controlling the browser session, the attackers can access accounts that are already logged in, effectively stealing the session data without needing a password [1, 2]. This method of session hijacking allows for a more seamless transition from infection to data theft [1].

BleepingComputer said the malware includes a streaming module that allows the attacker to interactively control the victim's web browser [1]. This capability distinguishes AmnesiaStealer from simpler infostealers that only copy files from a hard drive [1].

The malware affects macOS devices worldwide [1, 2, 3]. Users are encouraged to be cautious of suspicious prompts, and lures that request browser interactions or system changes [1, 3].

AmnesiaStealer targets macOS users via ClickFix attacks.

The emergence of AmnesiaStealer represents a shift toward interactive session hijacking on macOS. Unlike static data theft, where malware simply copies stored passwords, the use of the Chrome DevTools Protocol allows attackers to operate within an active, authenticated session. This means that even if a user has strong passwords, the attacker can bypass the login process entirely by hijacking the live session token.