Urgent.News

One page, thousands of outlets. See who else covered it.

Editions

Tech

Apple Mac Malware Lets Attackers Control Browser Sessions After Infection

AmnesiaStealer malware targets macOS with data theft and remote browser-session control, potentially exposing accounts already open on compromised Macs. The post Apple Mac Malware Lets Attackers Control Browser Sessions After Infection appeared first on TechRepublic .

<AmnesiaStealer> is an infostealer malware targeting macOS systems. This malicious software can steal data and gain remote access to browser sessions, putting user accounts at risk even after the initial infection. A routine download that seems harmless can lead to a more serious problem for Mac users. Jamf Threat Labs discovered an AmnesiaStealer campaign that spreads across macOS devices through a fake software download.

After the malware infiltrates the system, attackers can maintain control over browser sessions. The attack begins with a user running a Terminal command, but the real threat emerges later. The malware arrives through a counterfeit GitHub-style page, prompting users to copy an encoded command into Terminal using a ClickFix attack chain.

Once executed, AmnesiaStealer downloads and launches, collecting sensitive information from the device. The malware primarily targets browser data, the macOS Keychain, Apple Notes, and Telegram. Additionally, it can download an optional component called stream_module, which can copy a Chromium browser profile and launch another browser instance discreetly.

This copied data maintains authenticated sessions, allowing attackers to see what's displayed in the browser and send keyboard or mouse input back to the compromised system. If you use a Mac for work, consider this malware infection as more than just a malware removal process. Stolen session cookies could lead to unauthorized access to company email or cloud services, depending on your role and access.

In such cases, it's crucial to take the affected device offline, contact your IT or security team, and revoke active sessions. After the infection, run credential recovery alongside endpoint investigation to ensure all potential threats are addressed.

Written by urgent.news from TechRepublic's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techrepublic.com →

More in Tech

GSoC 2026 - Week 11

Week 11 of my Google Summer of Code journey with CircuitVerse (August 3rd to August 9th) was all about one thing: testing the canonical pipeline against real circuits.

  • Week 11 of GSoC 2026 focused on testing CircuitVerse's canonical import/export pipeline.
  • Aboo proposed downloading Editor's Picks circuit data for faster, reliable tests.
  • Many real circuits failed round trip, revealing lost information in the pipeline.

More from Monday 17 August →