ClickFix AmnesiaStealer distribution campaign targeting mac users
Campaign
Summary
Hide ▲
Show ▼
A ClickFix distribution campaign is pushing AmnesiaStealer onto mac users, increasing the risk of credential theft and browser-session hijacking. The lure uses a counterfeit GitHub download page and copy-paste social engineering to get victims to run a malicious command. Once installed, the payload stages data theft and can give operators hidden control over browser sessions.
Related Happenings
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware Activity
H score29
First: 14.08.2026 13:45
Last: 14.08.2026 13:45
Sources 1
How related:
A new macOS infostealer is being distributed via ClickFix social engineering attacks, researchers from Jamf have warned.
About this happening:
The AmnesiaStealer macOS infostealer is being spread through ClickFix social engineering, putting infected Macs at risk of credential theft, browser data theft...
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware ActivityHow related: A new macOS infostealer is being distributed via ClickFix social engineering attacks, researchers from Jamf have warned.
About this happening: The AmnesiaStealer macOS infostealer is being spread through ClickFix social engineering, putting infected Macs at risk of credential theft, browser data theft...
ClickFix macOS Terminal-command lure campaign
Campaign
H score42
First: 07.08.2026 01:37
Last: 07.08.2026 01:37
Sources 1
About this happening:
The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple K...
ClickFix macOS Terminal-command lure campaign
CampaignAbout this happening: The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple K...
DOUBLECUP ClickFix-delivered CountLoader and DeviceManager malware activity
Malware Activity
H score22
First: 03.08.2026 23:01
Last: 03.08.2026 23:01
Sources 1
About this happening:
DOUBLECUP is a Russian loader-as-a-service active since early June 2026 that uses ClickFix lures and browser-cached steganographic PNGs to deliver CountLoade...
DOUBLECUP ClickFix-delivered CountLoader and DeviceManager malware activity
Malware ActivityAbout this happening: DOUBLECUP is a Russian loader-as-a-service active since early June 2026 that uses ClickFix lures and browser-cached steganographic PNGs to deliver CountLoade...
DOUBLECUP loader-as-a-service expands ClickFix campaign tooling for Windows and macOS
Threat Actor Meta
H score28
First: 03.08.2026 23:01
Last: 03.08.2026 23:01
Sources 1
About this happening:
DOUBLECUP is a Russian loader-as-a-service that packages ClickFix campaign tooling and has been active since early June 2026, according to SOCRadar. It supplie...
DOUBLECUP loader-as-a-service expands ClickFix campaign tooling for Windows and macOS
Threat Actor MetaAbout this happening: DOUBLECUP is a Russian loader-as-a-service that packages ClickFix campaign tooling and has been active since early June 2026, according to SOCRadar. It supplie...
DOUBLECUP customer ClickFix campaign targeting impersonated SaaS login pages
Campaign
H score39
First: 03.08.2026 23:01
Last: 03.08.2026 23:01
Sources 1
About this happening:
The DOUBLECUP ClickFix campaign uses fake CAPTCHA prompts on impersonated NetSuite, Odoo, HubSpot, and Salesforce login pages to trick visitors into runnin...
DOUBLECUP customer ClickFix campaign targeting impersonated SaaS login pages
CampaignAbout this happening: The DOUBLECUP ClickFix campaign uses fake CAPTCHA prompts on impersonated NetSuite, Odoo, HubSpot, and Salesforce login pages to trick visitors into runnin...
Timeline
-
13.08.2026 03:00 2 articles · 1d ago
Jamf flags AmnesiaStealer ClickFix distribution to mac users
Initial DisclosureJamf reported a Rust macOS infostealer called AmnesiaStealer being distributed to mac users through ClickFix social engineering. The lure uses a counterfeit GitHub download page and a copy-and-paste command to launch a malicious script that installs the payload, which is designed to harvest credentials, browser data and live sessions.
Show sources
- Novel macOS Infostealer AmnesiaStealer Spread via ClickFix — www.infosecurity-magazine.com — 14.08.2026 13:45
- Novel macOS Infostealer AmnesiaStealer Spread via ClickFix — www.infosecurity-magazine.com — 14.08.2026 13:45