AmnesiaStealer macOS infostealer distributed via ClickFix
Malware Activity
Summary
Hide ▲
Show ▼
The AmnesiaStealer macOS infostealer is being spread through ClickFix social engineering, putting infected Macs at risk of credential theft, browser data theft, and live-session hijacking. The malware uses a counterfeit GitHub download lure and a self-deleting script to install itself while hiding activity from users. It then launches a remote-controlled second stage that can drive Chromium-family browsers and steal cookies in plaintext through the DevTools protocol.
Related Happenings
ClickFix AmnesiaStealer distribution campaign targeting mac users
Campaign
H score34
First: 14.08.2026 13:45
Last: 14.08.2026 13:45
Sources 1
How related:
The Jamf report, published on August 13, highlighted the attackers’ use of ClickFix to distribute AmnesiaStealer to mac users.
About this happening:
A ClickFix distribution campaign is pushing AmnesiaStealer onto mac users, increasing the risk of credential theft and browser-session hijacking. The lure uses...
ClickFix AmnesiaStealer distribution campaign targeting mac users
CampaignHow related: The Jamf report, published on August 13, highlighted the attackers’ use of ClickFix to distribute AmnesiaStealer to mac users.
About this happening: A ClickFix distribution campaign is pushing AmnesiaStealer onto mac users, increasing the risk of credential theft and browser-session hijacking. The lure uses...
ClickFix macOS Terminal-command lure campaign
Campaign
H score42
First: 07.08.2026 01:37
Last: 07.08.2026 01:37
Sources 1
About this happening:
The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple K...
ClickFix macOS Terminal-command lure campaign
CampaignAbout this happening: The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple K...
XCSSET v40 macOS malware activity via compromised Xcode projects
Malware Activity
H score30
First: 04.08.2026 22:03
Last: 04.08.2026 22:03
Sources 1
About this happening:
XCSSET v40 has resurfaced on macOS through compromised Xcode projects and GitHub repositories, putting thousands of users at risk of credential theft and data...
XCSSET v40 macOS malware activity via compromised Xcode projects
Malware ActivityAbout this happening: XCSSET v40 has resurfaced on macOS through compromised Xcode projects and GitHub repositories, putting thousands of users at risk of credential theft and data...
DOUBLECUP ClickFix-delivered CountLoader and DeviceManager malware activity
Malware Activity
H score22
First: 03.08.2026 23:01
Last: 03.08.2026 23:01
Sources 1
About this happening:
DOUBLECUP is a Russian loader-as-a-service active since early June 2026 that uses ClickFix lures and browser-cached steganographic PNGs to deliver CountLoade...
DOUBLECUP ClickFix-delivered CountLoader and DeviceManager malware activity
Malware ActivityAbout this happening: DOUBLECUP is a Russian loader-as-a-service active since early June 2026 that uses ClickFix lures and browser-cached steganographic PNGs to deliver CountLoade...
DOUBLECUP loader-as-a-service expands ClickFix campaign tooling for Windows and macOS
Threat Actor Meta
H score28
First: 03.08.2026 23:01
Last: 03.08.2026 23:01
Sources 1
About this happening:
DOUBLECUP is a Russian loader-as-a-service that packages ClickFix campaign tooling and has been active since early June 2026, according to SOCRadar. It supplie...
DOUBLECUP loader-as-a-service expands ClickFix campaign tooling for Windows and macOS
Threat Actor MetaAbout this happening: DOUBLECUP is a Russian loader-as-a-service that packages ClickFix campaign tooling and has been active since early June 2026, according to SOCRadar. It supplie...
Timeline
-
14.08.2026 13:45 2 articles · 1h ago
Jamf identifies AmnesiaStealer spreading through ClickFix on macOS
Initial DisclosureJamf reported a new Rust macOS infostealer called AmnesiaStealer spreading through ClickFix social engineering against mac users. The lure uses a counterfeit GitHub download page and a self-deleting script to execute the malware, which harvests credentials, browser data and live sessions, avoids macOS permission prompts, and launches a hidden second stage that can take interactive control of Chromium-family browsers and steal cookies in plaintext.
Show sources
- Novel macOS Infostealer AmnesiaStealer Spread via ClickFix — www.infosecurity-magazine.com — 14.08.2026 13:45
- Novel macOS Infostealer AmnesiaStealer Spread via ClickFix — www.infosecurity-magazine.com — 14.08.2026 13:45