{
  "id": 1542582,
  "title": "Apple Mac Malware Lets Attackers Control Browser Sessions After Infection",
  "url": "https://urgent.news/2026/08/17/apple-mac-malware-lets-attackers-control-browser-sessions-after",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-17T11:24:10.000Z",
  "source": {
    "name": "TechRepublic",
    "slug": "techrepublic",
    "url": "https://www.techrepublic.com/article/news-amnesiastealer-mac-malware/"
  },
  "original_language": "en",
  "account": "<AmnesiaStealer> is an infostealer malware targeting macOS systems. This malicious software can steal data and gain remote access to browser sessions, putting user accounts at risk even after the initial infection. A routine download that seems harmless can lead to a more serious problem for Mac users. Jamf Threat Labs discovered an AmnesiaStealer campaign that spreads across macOS devices through a fake software download. After the malware infiltrates the system, attackers can maintain control over browser sessions. The attack begins with a user running a Terminal command, but the real threat emerges later. The malware arrives through a counterfeit GitHub-style page, prompting users to copy an encoded command into Terminal using a ClickFix attack chain. Once executed, AmnesiaStealer downloads and launches, collecting sensitive information from the device. The malware primarily targets browser data, the macOS Keychain, Apple Notes, and Telegram. Additionally, it can download an optional component called stream_module, which can copy a Chromium browser profile and launch another browser instance discreetly. This copied data maintains authenticated sessions, allowing attackers to see what's displayed in the browser and send keyboard or mouse input back to the compromised system. If you use a Mac for work, consider this malware infection as more than just a malware removal process. Stolen session cookies could lead to unauthorized access to company email or cloud services, depending on your role and access. In such cases, it's crucial to take the affected device offline, contact your IT or security team, and revoke active sessions. After the infection, run credential recovery alongside endpoint investigation to ensure all potential threats are addressed.",
  "summary": "AmnesiaStealer malware targets macOS with data theft and remote browser-session control, potentially exposing accounts already open on compromised Macs. The post Apple Mac Malware Lets Attackers Control Browser Sessions After Infection appeared first on TechRepublic .",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}