Skip to main content
← All Articles

Tag

#ClickFix

17 articles

Advertisement

DriveSurge: Hijacking Thousands of Sites for ClickFix, FakeUpdate Malware
HIGH
Threat Intel

DriveSurge: Hijacking Thousands of Sites for ClickFix, FakeUpdate Malware

DriveSurge, a wide-scale IAB operation, hijacks thousands of trusted websites using a malicious TDS, redirecting users to sites distributing ClickFix and FakeUpdate

Runtime Rebel Intel
4 min read·Jun 2, 2026
TH
HIGH
Threat Intel

DriveSurge Campaigns: Detecting ClickFix and FakeUpdate Overlays

DriveSurge threat actors have hijacked thousands of sites to deploy ClickFix and FakeUpdate overlays, delivering info-stealers via deceptive browser alerts.

Runtime Rebel Intel
3 min read·Jun 2, 2026
CVE-2026-26980: Ghost CMS SQL Injection Leads to ClickFix Attacks
CRITICAL
Vulnerabilities

CVE-2026-26980: Ghost CMS SQL Injection Leads to ClickFix Attacks

Attackers exploit CVE-2026-26980 in Ghost CMS to compromise 700+ websites, deploying ClickFix malware that tricks users into executing malicious scripts.

Runtime Rebel Intel
4 min read·May 25, 2026
VU
CRITICAL
Vulnerabilities

CVE-2025-26980: Ghost CMS SQL Injection Exploited in ClickFix Campaign

A critical SQL injection vulnerability in Ghost CMS (CVE-2025-26980) is being exploited to deliver ClickFix malware through malicious JavaScript injections.

Runtime Rebel Intel
3 min read·May 24, 2026
TH
HIGH
Threat Intel

ClickFix Attacks Distribute Vidar Stealer: ACSC Warning & Mitigation

The ACSC warns Australian organizations of active ClickFix social engineering attacks deploying Vidar Stealer malware, risking data theft. Learn detection and mitigation.

Runtime Rebel Intel
4 min read·May 7, 2026
Sapphire Sleet's ClickFix: North Korea Targets macOS Users
HIGH
Threat Intel

Sapphire Sleet's ClickFix: North Korea Targets macOS Users

North Korea-backed Sapphire Sleet is deploying ClickFix malware via fake job offers and phony Zoom updates to steal macOS user credentials and data. Learn how to detect

Runtime Rebel Intel
4 min read·Apr 16, 2026
MA
HIGH
Malware

DeepLoad Malware: Analysis of ClickFix Attacks and Mitigation

DeepLoad malware, observed in ClickFix attacks, steals credentials, installs malicious browser extensions, and propagates via USB drives. Learn TTPs and defense

Runtime Rebel Intel
4 min read·Apr 1, 2026
DeepLoad Malware Leverages ClickFix, WMI for Browser Credential Theft
HIGH
Malware

DeepLoad Malware Leverages ClickFix, WMI for Browser Credential Theft

DeepLoad malware leverages ClickFix social engineering and WMI for persistence to steal browser credentials, employing AI-assisted obfuscation for evasion.

Runtime Rebel Intel
4 min read·Mar 30, 2026
TH
MEDIUM
Threat Intel

macOS Terminal ClickFix Protections: Blocking Malicious Shell Commands

Apple introduces Terminal warnings in macOS Sequoia 15.2 to combat ClickFix social engineering attacks that trick users into executing malicious shell scripts.

Runtime Rebel Intel
3 min read·Mar 30, 2026
MA
HIGH
Malware

Infinity Stealer macOS Malware: Analyzing ClickFix Lures and Payloads

Infinity Stealer targets macOS via ClickFix social engineering. Learn how this Nuitka-compiled malware steals browser data, crypto wallets, and Keychain info.

Runtime Rebel Intel
3 min read·Mar 28, 2026
TH
HIGH
Threat Intel

ClickFix Social Engineering Drops Infiniti Stealer on macOS

Attackers use fake Cloudflare CAPTCHA pages and ClickFix tactics to deliver the Python-based Infiniti Stealer to macOS systems via terminal commands.

Runtime Rebel Intel
4 min read·Mar 28, 2026
ClickFix Social Engineering Clusters Target Windows and macOS Systems
HIGH
Threat Intel

ClickFix Social Engineering Clusters Target Windows and macOS Systems

Insikt Group identifies five ClickFix clusters using obfuscated commands to exploit native system tools via fake browser error overlays on Windows and macOS.

Runtime Rebel Intel
4 min read·Mar 25, 2026