
AmnesiaStealer Malware on macOS Takes Live Control of Chromium Browser Sessions
Newly reported macOS malware called AmnesiaStealer hijacks sessions in Chromium-based browsers, potentially giving attackers real-time control of a victim's browser and access to logged-in accounts.
A new threat for Mac users has surfaced, according to a security headline from The Hacker News. A piece of malware called AmnesiaStealer is reportedly targeting macOS, the operating system that runs Apple computers, and hijacking sessions in Chromium-based browsers. Chromium is an open-source browser project that forms the foundation for popular browsers such as Google Chrome, Microsoft Edge, Brave, and Opera. By compromising these browser sessions, AmnesiaStealer can hand attackers live control of a victim's browser, which is a serious risk for anyone who uses a Mac to access websites, online banking, or business applications.
To understand the danger, it helps to know what a browser session is. When you log into a website, the site gives your browser a small piece of data called a session cookie. This cookie acts like a temporary ID card that proves you have already entered your username and password. As long as that cookie is valid, the website recognizes you and keeps you logged in. Session hijacking is a type of attack where malware steals that session cookie. Once the attacker has it, they can pretend to be you on that website without needing your password. AmnesiaStealer appears to focus on stealing these session cookies specifically from Chromium-based browsers on macOS.
What makes AmnesiaStealer particularly alarming is the promise of live browser control. Stealing a session cookie usually lets an attacker impersonate you on a website from their own computer, but it does not let them see your screen or interact with your browser directly. Live browser control goes further: it means the attacker can see and operate your browser as if they were sitting at your keyboard. They could open new tabs, visit other sites, click on links, read your emails, or make purchases using accounts that are already logged in. This kind of real-time access is much harder to detect and stop than a simple cookie theft, and it dramatically increases the harm an attacker can do.
For website owners and businesses, this threat is especially important. If a customer or an employee uses a Mac and becomes infected with AmnesiaStealer, an attacker could take over their account on your website. For a customer, that might mean unauthorized orders, stolen personal information, or changes to their account settings. For an employee or administrator, the consequences could be even worse: an attacker with a live hijacked session could access internal dashboards, view private data, or even take control of the website itself if the victim has administrative privileges. This kind of breach can damage customer trust, lead to financial losses, and require costly incident response.
The exact method by which AmnesiaStealer is delivered is not described in the headline, but malware like this often spreads through malicious downloads, fake software updates, or phishing emails that trick users into installing harmful files. Regardless of how it arrives, the impact is clear: any Mac user whose Chromium browser session is hijacked could lose control of their online accounts. Users should stay alert and avoid installing software from untrusted sources, and website owners should consider how they can help protect their visitors and their own infrastructure from this class of threat.
Fortunately, there are practical steps that ordinary users can take to reduce the risk. Keeping your Mac's operating system and your browser up to date is essential, because updates often include security fixes. Enabling two-factor authentication on important accounts adds a second layer of protection, so that even if a session cookie is stolen, the attacker may not be able to get in without the extra code. Users should also regularly review the active sessions or logged-in devices listed in their important accounts and log out of any they do not recognize. Installing a reputable security tool on your Mac can help detect and block malware like AmnesiaStealer before it can do damage.
For website owners, protecting your own systems and helping your users stay safe is critical. AEU-I, the security-first IT and infrastructure consulting service from AEU Group, helps organizations assess and strengthen their defenses against session hijacking and browser-based threats. By working with security experts, businesses can better understand risks like AmnesiaStealer and put controls in place to protect both their own operations and their customers.
How to Protect Yourself
- Keep your Mac's operating system and your browser updated to the latest version, because updates often fix security holes.
- Turn on two-factor authentication for your important online accounts, so a stolen session cookie alone is not enough for an attacker to get in.
- Regularly check the list of active sessions or logged-in devices in your important accounts and log out of any you do not recognize.
- Only download and install software from official app stores or trusted developer websites, and avoid clicking on unexpected links or attachments.
- Use a reputable security or antivirus program on your Mac and keep it up to date to help catch malware like AmnesiaStealer.