Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

AmnesiaStealer Hijacks Chromium Sessions on macOS, Stealing Browser Cookies and Tokens

Researchers disclosed AmnesiaStealer, a Rust‑based macOS stealer that hijacks Chromium browsers to exfiltrate session cookies. The malware is distributed via a counterfeit GitHub download page, highlighting gaps in access‑control and security‑awareness practices that SOC 2 programs must address.

LiveThreat™ Intelligence · 📅 August 17, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
4 recommended
📰
Source
thehackernews.com

AmnesiaStealer Hijacks Chromium Sessions on macOS, Stealing Browser Cookies and Tokens

What Happened — Researchers have identified a new macOS‑focused, Rust‑based information stealer named AmnesiaStealer. The malware hijacks Chromium‑based browsers (Chrome, Edge, Brave, etc.) to extract session cookies and authentication tokens. It is delivered via a counterfeit “Download for macOS” page on GitHub that mimics a verified publisher and uses a click‑jacking lure to trick users into installing the malicious binary.

Why It Matters for Compliance & Audit Readiness

  • The incident exemplifies a failure of logical‑access controls and credential‑handling policies that SOC 2 CC6.1 (Logical Access) is designed to mitigate.
  • Continuous monitoring of endpoint activity and privileged‑access logs provides the audit evidence needed to demonstrate that unauthorized session‑data exfiltration is detected and contained.
  • Security awareness training and supply‑chain vetting are core controls (CC1.1, CC1.2) that help prevent users from installing counterfeit software.

Who Is Affected — Organizations with macOS workstations and Chromium‑based browsers, notably technology SaaS providers, cloud‑infrastructure teams, and any enterprise that permits browser‑based access to internal services.

Recommended Actions —

  • Map the incident to SOC 2 CC6.1 (Logical Access) and CC1.2 (Security Awareness) controls; verify that MFA and least‑privilege policies are enforced for all browser sessions.
  • Deploy endpoint‑detection‑and‑response (EDR) rules to flag unknown Rust binaries and monitor for abnormal Chromium profile access.
  • Conduct a supply‑chain review of software download sources; enforce code‑signing verification for all macOS installers.
  • Refresh security‑awareness training to include counterfeit‑download and click‑jacking tactics.

Source: The Hacker News

Technical Notes — The stealer is a multi‑stage Rust binary that hijacks Chromium’s local storage files (Cookies, Local Storage) to harvest session tokens. Distribution relies on a fake GitHub release page with a click‑jacking overlay that tricks users into clicking “Download.” No public CVE has been assigned yet. Source: [The Hacker News]

📰 Original Source
https://thehackernews.com/2026/08/amnesiastealer-hijacks-chromium.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →