ClickFix AmnesiaStealer distribution campaign targeting mac users
Campaign
Summary
Hide ▲
Show ▼
A ClickFix campaign is distributing AmnesiaStealer to macOS users through a counterfeit GitHub "Download for macOS" page and a copy-and-paste command that launches a malicious loader. Jamf said the Rust-based infostealer harvests credentials, browser data, Apple Notes, Telegram, Safari, and iCloud Keychain content, and uses a root LaunchDaemon that impersonates Apple's crash reporting service for persistence. The newer analysis adds stream_module and remote_stream, which copy a victim’s Chromium profile into a hidden headless browser and let the operator drive authenticated sessions through WebSocket and Chrome DevTools Protocol channels on Google Chrome, Microsoft Edge, Vivaldi, Arc, Opera, Brave, and Chromium.
Related Happenings
Fake Codex download campaign using Google Sites and ClickFix
Campaign
H score35
First: 24.08.2026 18:00
Last: 24.08.2026 18:00
Sources 1
About this happening:
The fake Codex download campaign is using sponsored search results, Google Sites lures, and ClickFix instructions to push macOS users into running malware. The...
Fake Codex download campaign using Google Sites and ClickFix
CampaignAbout this happening: The fake Codex download campaign is using sponsored search results, Google Sites lures, and ClickFix instructions to push macOS users into running malware. The...
Sysmon detection for Chrome and Edge process injection during CDP-enabled post-exploitation
Defensive Guidance
H score11
First: 14.08.2026 14:07
Last: 14.08.2026 14:07
Sources 1
About this happening:
A concrete Sysmon hunt for chrome.exe and msedge.exe injection now helps Windows defenders spot CDP-enabled post-exploitation before authenticated browser sessions...
Sysmon detection for Chrome and Edge process injection during CDP-enabled post-exploitation
Defensive GuidanceAbout this happening: A concrete Sysmon hunt for chrome.exe and msedge.exe injection now helps Windows defenders spot CDP-enabled post-exploitation before authenticated browser sessions...
CDP-Enable-BOF activates Chrome DevTools Protocol inside live Windows browsers for post-exploitation session access
Technical Analysis
H score23
First: 14.08.2026 14:07
Last: 14.08.2026 14:07
Sources 1
About this happening:
CDP-Enable-BOF now enables Chrome DevTools Protocol access inside a live Google Chrome or Microsoft Edge process on Windows, raising the risk of cookie theft...
CDP-Enable-BOF activates Chrome DevTools Protocol inside live Windows browsers for post-exploitation session access
Technical AnalysisAbout this happening: CDP-Enable-BOF now enables Chrome DevTools Protocol access inside a live Google Chrome or Microsoft Edge process on Windows, raising the risk of cookie theft...
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware Activity
H score16
First: 14.08.2026 13:45
Last: 14.08.2026 13:45
Sources 1
How related:
Cybersecurity researchers have disclosed details of a new macOS-oriented, Rust-based information stealer called AmnesiaStealer that's capable of hijacking Chromium web browsers to steal session data.
About this happening:
AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware ActivityHow related: Cybersecurity researchers have disclosed details of a new macOS-oriented, Rust-based information stealer called AmnesiaStealer that's capable of hijacking Chromium web browsers to steal session data.
About this happening: AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...
ClickFix macOS Terminal-command lure campaign
Campaign
H score42
First: 07.08.2026 01:37
Last: 07.08.2026 01:37
Sources 1
About this happening:
The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple K...
ClickFix macOS Terminal-command lure campaign
CampaignAbout this happening: The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple K...
Timeline
-
16.08.2026 18:07 2 articles · 11d ago
AmnesiaStealer stream_module hijacks authenticated Chromium sessions
Technical Analysis UpdateJamf described AmnesiaStealer's stream_module and remote_stream commands, which copy a victim's Chromium profile into a hidden headless browser and open WebSocket and Chrome DevTools Protocol channels through webSocketDebuggerUrl. The operator can issue navigation and mouse commands, receive live screencasts, and export or import cookies to operate online portals inside the victim's authenticated sessions on Google Chrome, Microsoft Edge, Vivaldi, Arc, Opera, Brave, and Chromium.
Show sources
- New AmnesiaStealer macOS malware hijacks browser sessions via remote control — www.bleepingcomputer.com — 16.08.2026 18:07
- AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS — thehackernews.com — 13.08.2026 16:43
-
13.08.2026 03:00 2 articles · 15d ago
Jamf flags AmnesiaStealer ClickFix distribution to mac users
Initial DisclosureJamf reported a Rust macOS infostealer called AmnesiaStealer being distributed to mac users through ClickFix social engineering. The lure uses a counterfeit GitHub download page and a copy-and-paste command to launch a malicious script that installs the payload, which is designed to harvest credentials, browser data and live sessions.
Show sources
- Novel macOS Infostealer AmnesiaStealer Spread via ClickFix — www.infosecurity-magazine.com — 14.08.2026 13:45
- Novel macOS Infostealer AmnesiaStealer Spread via ClickFix — www.infosecurity-magazine.com — 14.08.2026 13:45