Industry Insights · August 17, 2026

New AmnesiaStealer Malware Threatens macOS Users

AmnesiaStealer malware hijacks browser sessions via remote control, posing a serious threat to macOS users.

Recently, researchers have discovered a new malware called AmnesiaStealer that specifically targets macOS users. This malware is distributed through ClickFix attacks, utilizing a counterfeit GitHub download page to lure victims into executing commands that lead to the installation of the malware. A notable feature of AmnesiaStealer is its streaming module, which allows attackers to interactively control the victim's browser sessions. The malware can copy the victim's Chromium profile, including its authentication state, and load it into a hidden, headless browser on the infected system. This enables the attacker to access the victim's authenticated sessions without detection. According to analysis by Jamf, AmnesiaStealer can collect data from 16 Chromium-based browsers, as well as other sensitive information such as passwords, cryptocurrency wallets, Apple Notes, and documents. The distribution method of this malware includes using a fake GitHub download page to trick users into pasting commands into the terminal, which downloads and executes the malicious payload. Researchers highlight that AmnesiaStealer's streaming module can interact with the victim's browser via the Chrome DevTools Protocol (CDP), allowing attackers to control the victim's browser sessions in real-time. The emergence of this new malware serves as a reminder for users to remain vigilant while using macOS and to avoid executing commands from untrusted sources.

Sources