Novel macOS Infostealer AmnesiaStealer Spread via ClickFix
ID: 0b5427ef-0b17-5ce4-8664-ad059bb513ff
STIX ID: report--0b5427ef-0b17-5ce4-8664-ad059bb513ff
Feed Name: Infosecurity Magazine (News)
Jamf researchers warn of AmnesiaStealer, a Rust-based macOS infostealer distributed via ClickFix social-engineering lures that tricks users into running a silent installer. The malware harvests Apple Notes, Telegram, credentials (including unlocking keychain files), browser data and cookies, and deploys a remote-controlled second stage that clones browser profiles to provide live, stealthy operator control via the DevTools protocol; Jamf recommends enabling threat prevention, advanced threat controls, and web protection to block and report such threats.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
