
AmnesiaStealer Malware Gives Attackers Real-Time Control of Chromium Browsers on Macs
A new macOS threat called AmnesiaStealer hijacks logged-in Chromium browser sessions, letting attackers operate the browser as if they were the victim, putting website admin accounts at risk.
Security researchers have identified a piece of malicious software (malware) named AmnesiaStealer that targets Apple Mac computers running macOS. The malware focuses on Chromium, the open-source project that forms the foundation of popular browsers such as Google Chrome, Microsoft Edge, and Brave. Once it infects a Mac, AmnesiaStealer does not just quietly steal data; it hijacks the active browser session. In simple terms, a browser session is the period when you are logged into websites and your activity is connected to your account. Hijacking that session means the attacker can take over your browsing in real time.
The key danger is live browser control. Instead of copying saved passwords or files, AmnesiaStealer allows an attacker to see and use the victim's open tabs as if they were sitting in front of the computer. They can click buttons, read messages, make purchases, or change settings. Because the browser already has the victim's login cookies and active login state, the attacker may not need to know any passwords. Many websites trust the current browser session, so the attacker can bypass normal login screens. This is especially serious for website owners and IT administrators who stay logged into hosting dashboards, content management systems like WordPress, DNS control panels, or cloud services.
Macs are often considered less vulnerable than other systems, but AmnesiaStealer is a clear reminder that macOS is a valuable target. Because Chromium-based browsers store session data locally, malware that can read or modify browser memory can take over an active session. The attack does not need to break a password; it simply rides on the trust the browser has already established with a website. For a website owner, this could mean an attacker gains access to the site's admin panel, where they can install malicious code, steal customer information, or redirect payments.
For businesses and website operators, the consequences go beyond one infected computer. If an employee or administrator uses a Chromium browser to access the company's hosting control panel, domain registrar, or content management system, a hijacked session on that Mac gives the attacker the same level of access. They could alter DNS records to point a domain to a fraudulent server, inject malware into the website to infect visitors, or exfiltrate customer databases. Because the attacker operates in real time, they can also defeat some security checks that rely on normal user behavior.
To reduce the risk from AmnesiaStealer and similar session-stealing malware, users should keep macOS and all Chromium-based browsers fully updated, install software only from trusted sources, enable two-factor authentication wherever possible, and regularly review active sessions in important accounts. For organizations, endpoint monitoring and security awareness training are essential layers. AEU-I, the security-first IT and consulting arm of AEU Group, helps businesses assess and close gaps that session-stealing malware can exploit, from hardening endpoints to monitoring suspicious account activity.
How to Protect Yourself
- Update your Mac and your Chromium-based browser (such as Chrome, Edge, or Brave) as soon as updates are available, because updates fix known security holes.
- Download and install software only from the official Mac App Store or the developer's real website, never from pop-up ads or email attachments.
- Turn on two-factor authentication (a second login step, like a code sent to your phone) for your website admin, hosting, and email accounts so a stolen browser session alone cannot let someone in.
- Regularly check the list of signed-in devices or active sessions in your important accounts and sign out any you do not recognize.
- Use a reputable security program on your Mac and run regular scans to catch malware early.
- Avoid logging into sensitive websites on public Wi-Fi unless you use a private, encrypted connection, because attackers on the same network can sometimes intercept your session.