Find notable cyber news and cases, enriched with sources, timelines, and signals.

ClickFix AmnesiaStealer distribution campaign targeting mac users

Campaign
First reported
Last updated
Happening score
H score 22
3 unique sources, 3 articles

Summary

Hide ▲

A ClickFix campaign is distributing AmnesiaStealer to macOS users through a counterfeit GitHub "Download for macOS" page and a copy-and-paste command that launches a malicious loader. Jamf said the Rust-based infostealer harvests credentials, browser data, Apple Notes, Telegram, Safari, and iCloud Keychain content, and uses a root LaunchDaemon that impersonates Apple's crash reporting service for persistence. The newer analysis adds stream_module and remote_stream, which copy a victim’s Chromium profile into a hidden headless browser and let the operator drive authenticated sessions through WebSocket and Chrome DevTools Protocol channels on Google Chrome, Microsoft Edge, Vivaldi, Arc, Opera, Brave, and Chromium.

Related Happenings

Fake Codex download campaign using Google Sites and ClickFix

Campaign
H score35 First: 24.08.2026 18:00 Last: 24.08.2026 18:00 Sources 1

About this happening: The fake Codex download campaign is using sponsored search results, Google Sites lures, and ClickFix instructions to push macOS users into running malware. The...

Sysmon detection for Chrome and Edge process injection during CDP-enabled post-exploitation

Defensive Guidance
H score11 First: 14.08.2026 14:07 Last: 14.08.2026 14:07 Sources 1

About this happening: A concrete Sysmon hunt for chrome.exe and msedge.exe injection now helps Windows defenders spot CDP-enabled post-exploitation before authenticated browser sessions...

CDP-Enable-BOF activates Chrome DevTools Protocol inside live Windows browsers for post-exploitation session access

Technical Analysis
H score23 First: 14.08.2026 14:07 Last: 14.08.2026 14:07 Sources 1

About this happening: CDP-Enable-BOF now enables Chrome DevTools Protocol access inside a live Google Chrome or Microsoft Edge process on Windows, raising the risk of cookie theft...

AmnesiaStealer macOS infostealer distributed via ClickFix

Malware Activity
H score16 First: 14.08.2026 13:45 Last: 14.08.2026 13:45 Sources 1

How related: Cybersecurity researchers have disclosed details of a new macOS-oriented, Rust-based information stealer called AmnesiaStealer that's capable of hijacking Chromium web browsers to steal session data.

About this happening: AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...

ClickFix macOS Terminal-command lure campaign

Campaign
H score42 First: 07.08.2026 01:37 Last: 07.08.2026 01:37 Sources 1

About this happening: The ClickFix campaign is delivering a Go-based macOS stealer through Terminal commands pasted from lure pages, creating a path to browser password theft, Apple K...

Timeline

  1. 16.08.2026 18:07 2 articles · 11d ago

    AmnesiaStealer stream_module hijacks authenticated Chromium sessions

    Technical Analysis Update

    Jamf described AmnesiaStealer's stream_module and remote_stream commands, which copy a victim's Chromium profile into a hidden headless browser and open WebSocket and Chrome DevTools Protocol channels through webSocketDebuggerUrl. The operator can issue navigation and mouse commands, receive live screencasts, and export or import cookies to operate online portals inside the victim's authenticated sessions on Google Chrome, Microsoft Edge, Vivaldi, Arc, Opera, Brave, and Chromium.

    Show sources
  2. 13.08.2026 03:00 2 articles · 15d ago

    Jamf flags AmnesiaStealer ClickFix distribution to mac users

    Initial Disclosure

    Jamf reported a Rust macOS infostealer called AmnesiaStealer being distributed to mac users through ClickFix social engineering. The lure uses a counterfeit GitHub download page and a copy-and-paste command to launch a malicious script that installs the payload, which is designed to harvest credentials, browser data and live sessions.

    Show sources