ClickFix Delivers AmnesiaStealer to Target macOS Credentials and Browsers
The new Rust-based AmnesiaStealer malware uses ClickFix social engineering and counterfeit GitHub download pages to trick macOS users into executing a malicious Terminal command. The multi-stage infostealer collects credentials, Apple Notes, Telegram data, system information, and encrypted Keychain records while suppressing sounds and avoiding certain permission prompts. A second-stage module clones browser profiles and gives attackers hidden control over seven Chromium-based browsers, enabling live session interaction and plaintext cookie theft through the DevTools protocol. macOS users should avoid running commands from untrusted websites and enable threat prevention, web protection, and advanced security controls.
Reference: infosecurity-magazine.com