logo

Apple Mac Malware Lets Attackers Control Browser Sessions After Infection

ID: 3d731a47-d01d-5a9d-ad9d-ed1f5359e9dc

STIX ID: report--3d731a47-d01d-5a9d-ad9d-ed1f5359e9dc

Feed Name: TechRepublic Security

Threat Score
70/100

Date Published: 2026-08-17

Date Updated: 2026-08-17

Author: Liz Ticong

...
...

Jamf Threat Labs reported an AmnesiaStealer campaign targeting macOS via a counterfeit GitHub-style download that uses a user-executed Terminal command to install a shell script. The stealer collects browser data, macOS Keychain items, Apple Notes and Telegram data, and can download an optional "stream_module" to copy Chromium profiles and run a hidden browser instance that operators can view and control, potentially preserving authenticated sessions; organizations are advised to treat infected Macs as broader incidents, isolate devices, revoke sessions from clean endpoints, and reset credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.