INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

ClickFix Used to Spread Novel macOS Infostealer AmnesiaStealer

| 2026-08-14 10:45 MEDIUM LOW DATA BREACH MALWARE & BOTNETS PHISHING & SOCIAL ENGINEERING
Executive Summary
AI-generated
A new macOS infostealer, dubbed AmnesiaStealer, is being distributed via ClickFix social engineering attacks, researchers from Jamf have warned. The attack began on August 1 and targeted mac users who entered a command that bypassed many anti-virus and cyber defense tools, categorizing the action as legitimate. This tactic preys on users' desire to fix problems themselves rather than alerting their IT team, making it effective at bypassing security protections. AmnesiaStealer has multiple stages and objectives, including harvesting credentials, browser data, and live sessions, with macOS-specific capabilities that make it a novel threat. The attackers used a counterfeit GitHub download page to distribute the malware, which executes a script that sets about malicious activities culminating in the exfiltration of a range of data, including Apple Notes and Telegram records. As of now, no specific number of affected devices or users has been reported.
Technical Mitigations AI-generated
• User Training (ATT&CK mitigation for Social Engineering): Reduces success of phishing/vishing/impersonation and modern “human interface” lures. • Audit (ATT&CK mitigation for Social Engineering): Enables correlation of email/identity/SaaS/endpoint activity that appears legitimate. • Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Campaign Unfolds TheCampaign Unfolds The
Target & Sectors
Global Scope
Incident Timeline
‎2026/08/14
Threat actors used ClickFix to distribute the AmnesiaStealer infostealer, a novel macOS malware with specific capabilities that bypassed anti-virus tools and exfiltrated data from Apple Notes and Telegram.
infrastructure Macos
Tactical Metrics
Metrics
infrastructure
‎Macos
Affected Product
Intelligence Sources
Infosecurity-Magazine 2026-08-14