← All security news

AmnesiaStealer Hijacks Mac Browsers

A Mac browser window is duplicated into a hidden ghost copy of itself, with a remote cursor icon driving the clone, representing an attacker cloning and remotely controlling a victim's already-logged-in browser session

Security researchers at Jamf have detailed a new macOS malware family called AmnesiaStealer, spread through fake GitHub download pages that lead victims through a "ClickFix" trick: a page tells you your download failed and instructs you to copy a command and paste it into the Terminal app to "fix" it. That single paste runs a script that installs the malware, which then shows a fake macOS password prompt to unlock the victim's Keychain, Apple Notes, and documents, and pulls saved passwords, cookies, and history from 16 different Chromium-based browsers, including Chrome, Edge, Brave, and Arc.

What sets AmnesiaStealer apart is what it does next. Rather than just exfiltrating stolen passwords for later use, it copies the victim's actual browser profile, including the tokens that keep you signed in, into a hidden, invisible browser window on the infected Mac. From there, the attacker can watch a live low-frame-rate view of that browser and drive it directly: click, type, scroll, open tabs, and browse company systems or online banking exactly as the victim would appear to be doing themselves. Because the session is already authenticated, this can sidestep the password and even multi-factor authentication checks that would normally stop a stolen-credential attack.

What this means for your business

The entry point here is entirely social engineering, not a software bug, which makes it stoppable with one clear rule: no legitimate installer, update, or "fix" ever asks you to paste a command into Terminal. Make sure everyone using a Mac in your business, especially anyone who handles finance, HR, or client accounts, knows to close the page and ignore any prompt that does. If a Mac is ever suspected of being compromised this way, a password reset alone will not undo the damage, since the attacker's access rides on the live session, not the password. Sign the affected accounts out of all active sessions (most banking, email, and SaaS admin panels have a "sign out of all devices" option), watch for any new-device or new-location sign-in alerts in the days after, and treat business-critical logins as needing a fresh password and a fresh MFA re-enrolment, not just a reset.

Questions about your own setup? contact@techleetsolutions.com
Sources: Jamf Threat Labs, BleepingComputer, The Hacker News