CybersecurityAugust 16, 2026· via BleepingComputer

AmnesiaStealer Targets macOS Users with Browser Hijacking

AmnesiaStealer Targets macOS Users with Browser Hijacking

Image : BleepingComputer

A new macOS malware called AmnesiaStealer is making waves by combining traditional data theft with real-time browser hijacking, giving attackers an alarming level of control over infected systems. Discovered by security researchers, this malware leverages ClickFix attacks—masquerading as legitimate software updates—to trick users into installing it. Once inside, AmnesiaStealer doesn’t just siphon off passwords or cookies; it embeds a streaming module that lets attackers interactively manipulate the victim’s browser, opening the door to fraud, unauthorized transactions, or further compromise.

A two-pronged threat

Unlike typical infostealers that quietly extract data before disappearing, AmnesiaStealer introduces a remote-control twist. The streaming module enables live session hijacking, meaning attackers can navigate the browser, access open tabs, or even fill out forms—all while the user remains oblivious. This capability turns stolen credentials from passive assets into active tools for cybercriminals, amplifying the damage beyond mere data exfiltration.

Security teams warn that this approach mirrors tactics seen in Windows-focused malware but is notably rare in macOS threats. The use of ClickFix—a decoy for fake software updates—highlights how attackers exploit user trust in familiar update prompts, particularly on Apple’s platform where such lures can be highly effective.

Why it matters

AmnesiaStealer underscores a growing trend: macOS is no longer a "safer" alternative for cybercriminals. The integration of interactive remote control into a data-stealing payload marks a significant escalation, as it transforms malware from a silent thief into an active participant in fraud. For macOS users, this means traditional defenses like password managers or endpoint protection may fall short—vigilance around unsolicited update prompts is now critical. The malware also signals that attackers are refining cross-platform strategies, blending stealth with real-time exploitation to maximize payoff.


Source: BleepingComputer. AI-assisted editorial synthesis — TechnoExpress.

Read the original source on BleepingComputer →

← Back to home