A newly identified macOS infostealer dubbed AmnesiaStealer is riding the well-established ClickFix social engineering wave, giving attackers live, covert control over victimsβ browsers and siphoning sensitive data from infected Macs.[1][8][9][13] Researchers at Jamf Threat Labs say the multi-stage Rust-based malware is being pushed through polished ClickFix lures, marking a significant evolution in macOS infostealers that target authenticated web sessions rather than just stored credentials.[1][9][13]
In the AmnesiaStealer campaign, victims are funneled to a counterfeit GitHub βDownload for macOSβ page that instructs them to paste a seemingly benign command into Terminal, a hallmark of the ClickFix technique.[1][9] That command quietly downloads and runs a shell script, which in turn launches a Rust infostealer and can later fetch an additional stream_module component on demand.[1][9][13] Once active, AmnesiaStealer harvests data from the macOS keychain, multiple browsers, Apple Notes and Telegram, and can hand operators hidden, interactive control of the victimβs Chromium browser to hijack authenticated sessions and steal cookie data.[1][8][9][13]
ClickFix, first documented in campaigns delivering Atomic macOS Stealer (AMOS) and other infostealers, is a social engineering method rather than an exploit, relying entirely on convincing users to execute attacker-supplied commands.[2][7][10][14] Previous research from Microsoft Defender, the Cloud Security Alliance, and others has traced ClickFix lures masquerading as macOS utilities, AI tool installers, CAPTCHA checks and even Script Editor workflows, all designed to make Terminal commands look like routine troubleshooting steps.[2][5][7][10][11][14][15] Those campaigns have been used to deploy families such as MacSync, Shub Stealer, AMOS, ClickLock and other modular macOS stealers, illustrating how ClickFix has become a reusable delivery pattern for diverse payloads.[2][6][7][12][14]
AmnesiaStealer fits squarely into that ecosystem but raises the stakes by shifting from simple data theft to real-time account takeover via browser session hijacking.[1][8][9][13] By stealing cookies and manipulating live Chromium sessions, operators can ride existing logins to cloud services, SaaS applications, developer platforms and cryptocurrency accounts, potentially bypassing multi-factor authentication in the process.[1][8][9][13] The infostealerβs ability to pull keychain entries, browser passwords, wallet data and messaging content further expands the blast radius, giving attackers a comprehensive snapshot of a userβs digital identity and access tokens on a compromised Mac.[1][5][6][9][13]
Researchers emphasize that AmnesiaStealer and ClickFix do not appear to exploit a specific macOS vulnerability or misconfiguration, but instead abuse legitimate system capabilities through user-approved commands.[1][7][10][15] No vendor advisory or CVE has been publicly tied to AmnesiaStealer to date, underscoring that traditional patch-centric defense offers limited protection against this class of threat.[1][7][10] Instead, defenders are urged to focus on user awareness around Terminal prompts, hardening macOS with strict controls on script execution, and monitoring for unusual command-line activity that chains curl or similar utilities into shell interpreters.[1][7][10][15]
Enterprises with macOS fleets are advised to review proxy and DNS logs for traffic to suspicious download domains associated with ClickFix-style campaigns and to hunt for evidence of unauthorized Terminal commands pasted from browser windows.[2][5][6][7][14] Deploying endpoint detection tuned to spot multi-stage script chains, infostealer behaviors targeting keychain and browser stores, and unexpected remote-control activity from browser processes can help catch AmnesiaStealer and related payloads before operators fully weaponize stolen sessions.[1][5][6][9][13] Given the rapid iteration of ClickFix lures and the expanding roster of macOS infostealers, security teams should treat this campaign as another warning that macOS is firmly in the crosshairs of credential-theft and session-hijacking operators.[1][2][7][9][13]
References
- AmnesiaStealer: macOS Infostealer That Hijacks Browsers – Jamf
- ClickFix campaign uses fake macOS utilities lures to deliver …
- New macOS ClickFix attack silently mounts DMGs to push …
- ClickFix Campaigns Spread MacSync macOS Infostealer via Fake AI …
- MacSync Infostealer: ClickFix Campaigns via Fake AI Installers
- AmnesiaStealer: macOS Infostealer That Hijacks Browsers
- Novel macOS Infostealer AmnesiaStealer Spread via ClickFix
- Think before you Click(Fix): Analyzing the ClickFix social … – Microsoft
- ClickFix finds a new way to infect Macs
- New ClickLock Stealer macOS Malware Spread via ClickFix …
- AmnesiaStealer macOS Malware Uses ClickFix to Hijack …
- ClickFix Campaign Uses Fake macOS Utilities to Deliver Infostealers
- ClickFix Malware Uses macOS Script Editor to Deliver Atomic Stealer
