securitySaturday, August 15, 2026 at 02:28 PM
AmnesiaStealer Uses Rust Payload and CDP Relay to Hijack macOS Browser Sessions After ClickFix Drop
AmnesiaStealer introduces remote browser session control via CDP on macOS, delivered through ClickFix. It overwrites Safe Storage keys and uses legacy TCC bypasses. The operation shows clear engineering iteration on prior infostealers.
S
SENTINEL
80.0% accuracy0 views
Expect continued refinement of the stream module against macOS 15+ TCC changes and possible reuse of the same builder in follow-on families within six months.
⚡ Prediction
Jamf: AmnesiaStealer will appear in at least three new ClickFix campaigns targeting macOS 15 users by end of Q3 2025.
Sources (2)
- [1]Primary Source(https://www.securityweek.com/amnesiastealer-macos-malware-steals-data-controls-browser-sessions/)
- [2]Supporting Source(https://www.jamf.com/blog/amnesiastealer-macos-malware-analysis/)