Find notable cyber news and cases, enriched with sources, timelines, and signals.

AmnesiaStealer macOS infostealer distributed via ClickFix

Malware Activity
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

The AmnesiaStealer macOS infostealer is being spread through ClickFix social engineering, putting infected Macs at risk of credential theft, browser data theft, and live-session hijacking. The malware uses a counterfeit GitHub download lure and a self-deleting script to install itself while hiding activity from users. It then launches a remote-controlled second stage that can drive Chromium-family browsers and steal cookies in plaintext through the DevTools protocol.

Related Happenings

ClickFix AmnesiaStealer distribution campaign targeting mac users

Campaign
H score34 First: 14.08.2026 13:45 Last: 14.08.2026 13:45 Sources 1

How related: The Jamf report, published on August 13, highlighted the attackers’ use of ClickFix to distribute AmnesiaStealer to mac users.

About this happening: A ClickFix distribution campaign is pushing AmnesiaStealer onto mac users, increasing the risk of credential theft and browser-session hijacking. The lure uses...

ClickFix macOS Terminal-command lure campaign

Campaign
H score42 First: 07.08.2026 01:37 Last: 07.08.2026 01:37 Sources 1

About this happening: The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple K...

XCSSET v40 macOS malware activity via compromised Xcode projects

Malware Activity
H score30 First: 04.08.2026 22:03 Last: 04.08.2026 22:03 Sources 1

About this happening: XCSSET v40 has resurfaced on macOS through compromised Xcode projects and GitHub repositories, putting thousands of users at risk of credential theft and data...

DOUBLECUP ClickFix-delivered CountLoader and DeviceManager malware activity

Malware Activity
H score22 First: 03.08.2026 23:01 Last: 03.08.2026 23:01 Sources 1

About this happening: DOUBLECUP is a Russian loader-as-a-service active since early June 2026 that uses ClickFix lures and browser-cached steganographic PNGs to deliver CountLoade...

DOUBLECUP loader-as-a-service expands ClickFix campaign tooling for Windows and macOS

Threat Actor Meta
H score28 First: 03.08.2026 23:01 Last: 03.08.2026 23:01 Sources 1

About this happening: DOUBLECUP is a Russian loader-as-a-service that packages ClickFix campaign tooling and has been active since early June 2026, according to SOCRadar. It supplie...

Timeline

  1. 14.08.2026 13:45 2 articles · 1h ago

    Jamf identifies AmnesiaStealer spreading through ClickFix on macOS

    Initial Disclosure

    Jamf reported a new Rust macOS infostealer called AmnesiaStealer spreading through ClickFix social engineering against mac users. The lure uses a counterfeit GitHub download page and a self-deleting script to execute the malware, which harvests credentials, browser data and live sessions, avoids macOS permission prompts, and launches a hidden second stage that can take interactive control of Chromium-family browsers and steal cookies in plaintext.

    Show sources