logo

Novel macOS Infostealer AmnesiaStealer Spread via ClickFix

ID: 0b5427ef-0b17-5ce4-8664-ad059bb513ff

STIX ID: report--0b5427ef-0b17-5ce4-8664-ad059bb513ff

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-08-14

Date Updated: 2026-08-14

...
...

Jamf researchers warn of AmnesiaStealer, a Rust-based macOS infostealer distributed via ClickFix social-engineering lures that tricks users into running a silent installer. The malware harvests Apple Notes, Telegram, credentials (including unlocking keychain files), browser data and cookies, and deploys a remote-controlled second stage that clones browser profiles to provide live, stealthy operator control via the DevTools protocol; Jamf recommends enabling threat prevention, advanced threat controls, and web protection to block and report such threats.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.