INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ClickFix Used to Spread Novel macOS Infostealer AmnesiaStealer
| 2026-08-14 10:45 MEDIUM LOW DATA BREACH MALWARE & BOTNETS PHISHING & SOCIAL ENGINEERING
Executive Summary
AI-generated
A new macOS infostealer, dubbed AmnesiaStealer, is being distributed via ClickFix social engineering attacks, researchers from Jamf have warned. The attack began on August 1 and targeted mac users who entered a command that bypassed many anti-virus and cyber defense tools, categorizing the action as legitimate. This tactic preys on users' desire to fix problems themselves rather than alerting their IT team, making it effective at bypassing security protections. AmnesiaStealer has multiple stages and objectives, including harvesting credentials, browser data, and live sessions, with macOS-specific capabilities that make it a novel threat. The attackers used a counterfeit GitHub download page to distribute the malware, which executes a script that sets about malicious activities culminating in the exfiltration of a range of data, including Apple Notes and Telegram records. As of now, no specific number of affected devices or users has been reported.
Technical Mitigations AI-generated
• User Training (ATT&CK mitigation for Social Engineering): Reduces success of phishing/vishing/impersonation and modern “human interface” lures.
• Audit (ATT&CK mitigation for Social Engineering): Enables correlation of email/identity/SaaS/endpoint activity that appears legitimate.
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Campaign Unfolds
TheCampaign Unfolds
The
Target & Sectors
Global Scope
Incident Timeline
2026/08/14
Threat actors used ClickFix to distribute the AmnesiaStealer infostealer, a novel macOS malware with specific capabilities that bypassed anti-virus tools and exfiltrated data from Apple Notes and Telegram.
Click on any entity below to view its context and source!
infrastructure
Macos
A new macOS infostealer is being distributed via ClickFix social engineering attacks, researchers from Jamf have warned.
Novel macOS Infostealer AmnesiaStealer Spread via ClickFix.
While its objectives overlap with other macOS infostealers such as
Atomic
(AMOS),
MacSync
and
CrashStealer
, the researchers noted that AmnesiaStealer has macOS-specific capabilities that make it a novel threat.
It contains OS version-branched logic that reaches for macOS bypasses that have been patched by Apple.
The researchers noted that this lure template is shared across multiple macOS infostealer families.
AmnesiaStealer first harvests data from Apple Notes and Telegram, writing commands that ensure it avoids triggering a macOS permission (TCC) prompt.
Jamf advised macOS users to configure threat prevention, advanced threat controls and web protection to Block and Report to help prevent the execution of similar threats.
Tactical Metrics
Metrics
infrastructure
Macos
Affected Product
Click for context!
A new macOS infostealer is being distributed via ClickFix social engineering attacks, researchers from Jamf have warned.
Novel macOS Infostealer AmnesiaStealer Spread via ClickFix.
While its objectives overlap with other macOS infostealers such as
Atomic
(AMOS),
MacSync
and
CrashStealer
, the researchers noted that AmnesiaStealer has macOS-specific capabilities that make it a novel threat.
It contains OS version-branched logic that reaches for macOS bypasses that have been patched by Apple.
The researchers noted that this lure template is shared across multiple macOS infostealer families.
AmnesiaStealer first harvests data from Apple Notes and Telegram, writing commands that ensure it avoids triggering a macOS permission (TCC) prompt.
Jamf advised macOS users to configure threat prevention, advanced threat controls and web protection to Block and Report to help prevent the execution of similar threats.
Intelligence Sources
Infosecurity-Magazine
2026-08-14
Novel macOS Infostealer AmnesiaStealer Spread via ClickFix
Infosecurity-Magazine
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T08:57
Comprehensive Tactical Telemetry
Highly Correlated Entities
15x
organisation
Identified Entity
ClickFix
entity
3x
tactic
Cyber Operation Type
Social Engineering
tactic
2x
timeline
Temporal Reference
August 13
date
Contextual Telemetry
Context Block
3 METRICS
industry
Targeted Sector
Defense
sector
infrastructure
Affected Product
Macos
software
campaign
Campaign
Campaign Unfolds
The
operation
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.