New AmnesiaStealer macOS malware hijacks browser sessions via remote control

By George Bailey   Published: 08/16/26   3 min read
New AmnesiaStealer macOS malware hijacks browser sessions via remote control

What Stands Out

BleepingComputer described AmnesiaStealer as a new macOS information stealer that uses ClickFix lures and then gives the operator more than simple data theft. The notable feature is a streaming module that lets the attacker interact with the victim's browser in real time.

That matters because the jump from credential theft to active browser control changes the risk profile. If the attacker can ride an already-authenticated browser session, the problem can move from malware cleanup into direct account abuse, token theft, and downstream SaaS exposure.

Why Browser Control Changes The Story

Many infostealer stories end with stolen files, passwords, or cookies. This one deserves more attention because interactive browser control can let the operator work inside the victim's existing sessions instead of waiting to replay credentials elsewhere.

That gives defenders a narrower response window. A user can believe they just clicked through a fake support or verification prompt while the attacker is already turning that moment into access to email, collaboration, cloud, or financial workflows visible in the browser.

Why ClickFix Still Matters

ClickFix keeps showing up because it turns a familiar security habit into an attacker advantage. The lure does not need an exotic exploit if it can pressure a user into running the wrong command, approving the wrong prompt, or trusting a fake repair flow.

That is the practical lesson here. The malware family name matters less than the delivery pattern and the fact that it keeps evolving into cleaner post-compromise control over the victim's environment.

What Teams Should Do Next

Treat this like a session-abuse story, not just a malware-family story.

What Teams May Be Underestimating

The easy mistake is to treat session hijacking as a browser or identity-team problem only. In reality it becomes a cross-functional problem fast because the browser is where users touch email, cloud consoles, support tools, finance apps, and collaboration platforms.

That is why this story is worth its own page. It is a reminder that real attacker leverage often comes from the active session layer, not just from whatever malware first landed on disk.

Source Context

CyberExperts used BleepingComputer's reporting as the primary source for this article and kept the focus on the two operator-relevant details that matter most: ClickFix delivery and the malware's ability to hijack live browser sessions through interactive remote control.

Related In The Daily Brief

See this item in The 5-Minute Cyber Brief

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.

Keep Reading