{"id":242679,"date":"2026-08-14T01:17:08","date_gmt":"2026-08-14T06:17:08","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2026\/08\/amnesiastealer-hijacks-chromium-sessions-to-give-attackers-live-browser-control-on-macos"},"modified":"2026-08-14T01:17:08","modified_gmt":"2026-08-14T06:17:08","slug":"amnesiastealer-hijacks-chromium-sessions-to-give-attackers-live-browser-control-on-macos","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2026\/08\/amnesiastealer-hijacks-chromium-sessions-to-give-attackers-live-browser-control-on-macos","title":{"rendered":"AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS"},"content":{"rendered":"<p><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/amnesiastealer-hijacks-chromium-sessions-to-give-attackers-live-browser-control-on-macos2.jpg\"><\/a><\/p>\n<p>\u201cIn effect, the remote_stream command turns an infected host into a live, operator-driven browser running the victim\u2019s authenticated sessions, which is a materially different level of access from file collection.\u201d<\/p>\n<p>While the overall objectives of the malware are consistent with other stealers like Atomic Stealer, MacSync, and CrashStealer, three different aspects set it apart: a builder-driven configuration, operating system version-branched logic that reaches for macOS bypasses already patched by Apple, and a remote-control second stage that allows attackers to steal user cookies and evade detection through a stealth script that patches browser fingerprinting APIs.<\/p>\n<p>AmnesiaStealer gets its name from a login page located at the root of the C2 host with the name \u201cAmnesia Panel.\u201d A failed login returns an error message in Russian, urging users to provide a correct login or password to sign in to the operator.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u201cIn effect, the remote_stream command turns an infected host into a live, operator-driven browser running the victim\u2019s authenticated sessions, which is a materially different level of access from file collection.\u201d While the overall objectives of the malware are consistent with other stealers like Atomic Stealer, MacSync, and CrashStealer, three different aspects set it apart: a [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34],"tags":[],"class_list":["post-242679","post","type-post","status-publish","format-standard","hentry","category-cybercrime-malcode"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/242679","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=242679"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/242679\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=242679"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=242679"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=242679"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}