Advertisement
Node.js Abuse: Attackers Deploy Malware via Trusted Runtime
Threat actors are leveraging Node.js as a signed, trusted tool to deploy various malicious payloads, evading detection in targeted attacks since February 2026.
ClickFix Campaign Exploits Polygon Blockchain for C2 Evasion
The ClickFix campaign compromises 31 organizations, dynamically updating its C2 server via EtherHiding and the Polygon blockchain.
WordlistLoader Evades Detection, Delivers Amatera Infostealer
WordlistLoader uses a novel text-based obfuscation to bypass security, deploying the Amatera infostealer in ClickFix-style campaigns, posing a significant threat.
AmnesiaStealer macOS Malware Hijacks Browser Sessions via Remote Control
AmnesiaStealer targets macOS users via ClickFix attacks, cloning Chromium profiles to enable live remote control of authenticated browser sessions.
ClickFix Attack Deploys macOS Infostealer for Crypto Theft
The ClickFix attack leverages a Go-based macOS infostealer to pilfer cryptocurrency, browser data, and Apple Keychain credentials via a Bash script loader.
Rogue AI Agents and Check Point Exploits: A Weekly Security Analysis
Analysis of OpenAI's rogue AI agents, active Check Point VPN exploitation, and the emergence of Slopsquatting and ClickFix phishing lures in the wild.
Advertisement
Steam Forum ClickFix Attacks Distribute XMRig Cryptominers
Attackers exploit Steam forums using ClickFix social engineering to trick gamers into installing XMRig cryptominers via malicious PowerShell commands.
BlueNoroff Zoom Phishing Kit Targets Crypto Wallets
BlueNoroff uses a custom phishing kit to profile crypto wallets before delivering malware through impersonated Zoom and Microsoft Teams platforms.
UAC-0145 ClickFix Strategy: How Sandworm Targets Ukraine with Malware
Russian threat actor UAC-0145 uses deceptive ClickFix CAPTCHAs to deliver data-stealing malware to Ukrainian targets. Learn how to detect and mitigate these TTPs.
TELEPUZ Malware: Analyzing Modular Payloads in ClickFix Campaigns
TELEPUZ is a new modular malware spreading via ClickFix lures to steal sensitive data and execute remote commands on compromised Windows systems.
ClickFix Ecosystem: Evasive Attack-as-a-Service & YARA Detection
The ClickFix ecosystem offers rented, evasive attack vectors bypassing AV/EDR. Learn why YARA analysis is crucial for detecting this scalable threat.
SCMBANKER Malware: Analyzing ClickFix Lures Targeting Mexican Banks
Elastic Security Labs tracks REF6045, deploying SCMBANKER malware via fake ClickFix CAPTCHA pages to compromise Mexican banking users.
ClickFix Social Engineering: How to Detect Fake Browser Update Attacks
ClickFix has become the dominant malware delivery method. Learn how attackers use fake browser error overlays to trick users into executing malicious PowerShell.
ClickFix Campaigns Expand Delivery with New Loaders and Fake Lures
ClickFix campaigns are now deploying BabaDeda, Lorem Ipsum, and Potemkin loaders through fake browser update social engineering lures.
Cyber Insurance Market Shifts: Rates Drop, Exclusions Widen
Organizations face reduced cyber insurance coverage despite dropping rates. Exclusions for social engineering attacks like ClickFix are widening, demanding policy…
DriveSurge: Hijacking Thousands of Sites for ClickFix, FakeUpdate Malware
DriveSurge, a wide-scale IAB operation, hijacks thousands of trusted websites using a malicious TDS, redirecting users to sites distributing ClickFix and FakeUpdate…
DriveSurge Campaigns: Detecting ClickFix and FakeUpdate Overlays
DriveSurge threat actors have hijacked thousands of sites to deploy ClickFix and FakeUpdate overlays, delivering info-stealers via deceptive browser alerts.
CVE-2026-26980: Ghost CMS SQL Injection Leads to ClickFix Attacks
Attackers exploit CVE-2026-26980 in Ghost CMS to compromise 700+ websites, deploying ClickFix malware that tricks users into executing malicious scripts.
CVE-2025-26980: Ghost CMS SQL Injection Exploited in ClickFix Campaign
A critical SQL injection vulnerability in Ghost CMS (CVE-2025-26980) is being exploited to deliver ClickFix malware through malicious JavaScript injections.
ClickFix Attacks Distribute Vidar Stealer: ACSC Warning & Mitigation
The ACSC warns Australian organizations of active ClickFix social engineering attacks deploying Vidar Stealer malware, risking data theft. Learn detection and mitigation.
Sapphire Sleet's ClickFix: North Korea Targets macOS Users
North Korea-backed Sapphire Sleet is deploying ClickFix malware via fake job offers and phony Zoom updates to steal macOS user credentials and data.
DeepLoad Malware: Analysis of ClickFix Attacks and Mitigation
DeepLoad malware, observed in ClickFix attacks, steals credentials, installs malicious browser extensions, and propagates via USB drives.
DeepLoad Malware Leverages ClickFix, WMI for Browser Credential Theft
DeepLoad malware leverages ClickFix social engineering and WMI for persistence to steal browser credentials, employing AI-assisted obfuscation for evasion.
macOS Terminal ClickFix Protections: Blocking Malicious Shell Commands
Apple introduces Terminal warnings in macOS Sequoia 15.2 to combat ClickFix social engineering attacks that trick users into executing malicious shell scripts.