www.infosecurity-magazine.com 8/14/2026, 11:01:03 AM · external

AmnesiaStealer macOS Infostealer Spreads Via Fake GitHub ClickFix

AmnesiaStealer macOS Infostealer Spreads Via Fake GitHub ClickFix
CyberSIXT Evidence Panel
Primary Source jamf.com

A new macOS infostealer named AmnesiaStealer has been discovered, spreading through ClickFix social engineering attacks. Researchers from Jamf highlighted its multi-stage process, allowing it to harvest sensitive information such as credentials and browser data. AmnesiaStealer employs tactics similar to other macOS infostealers but includes unique OS-specific capabilities, making it harder to detect.

The ClickFix approach uses a counterfeit GitHub download to manipulate users into executing malicious scripts, effectively bypassing security protocols. To evade detection during its operation, the malware mutes the system sound and avoids triggering macOS permissions. A second stage grants attackers remote control of the victim's browser, facilitating data theft without user awareness. Jamf recommends users enhance their security measures to mitigate such threats.

View Primary Source Via www.infosecurity-magazine.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline