Toggle light / dark theme

AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS

“In effect, the remote_stream command turns an infected host into a live, operator-driven browser running the victim’s authenticated sessions, which is a materially different level of access from file collection.”

While the overall objectives of the malware are consistent with other stealers like Atomic Stealer, MacSync, and CrashStealer, three different aspects set it apart: a builder-driven configuration, operating system version-branched logic that reaches for macOS bypasses already patched by Apple, and a remote-control second stage that allows attackers to steal user cookies and evade detection through a stealth script that patches browser fingerprinting APIs.

AmnesiaStealer gets its name from a login page located at the root of the C2 host with the name “Amnesia Panel.” A failed login returns an error message in Russian, urging users to provide a correct login or password to sign in to the operator.

Leave a Comment

Lifeboat Foundation respects your privacy! Your email address will not be published.

/* */