A new macOS infostealer named AmnesiaStealer has been discovered, spreading through ClickFix social engineering attacks. Researchers from Jamf highlighted its multi-stage process, allowing it to harvest sensitive information such as credentials and browser data. AmnesiaStealer employs tactics similar to other macOS infostealers but includes unique OS-specific capabilities, making it harder to detect.
The ClickFix approach uses a counterfeit GitHub download to manipulate users into executing malicious scripts, effectively bypassing security protocols. To evade detection during its operation, the malware mutes the system sound and avoids triggering macOS permissions. A second stage grants attackers remote control of the victim's browser, facilitating data theft without user awareness. Jamf recommends users enhance their security measures to mitigate such threats.