Skip to main content
← All Articles

Tag

#ClickFix

35 articles

Advertisement

Node.js Abuse: Attackers Deploy Malware via Trusted Runtime
MEDIUM
Threat Intel

Node.js Abuse: Attackers Deploy Malware via Trusted Runtime

Threat actors are leveraging Node.js as a signed, trusted tool to deploy various malicious payloads, evading detection in targeted attacks since February 2026.

Runtime Rebel Intel
4 min read · Sep 3, 2026
ClickFix Campaign Exploits Polygon Blockchain for C2 Evasion
HIGH
Threat Intel

ClickFix Campaign Exploits Polygon Blockchain for C2 Evasion

The ClickFix campaign compromises 31 organizations, dynamically updating its C2 server via EtherHiding and the Polygon blockchain.

Runtime Rebel Intel
4 min read · Sep 1, 2026
WordlistLoader Evades Detection, Delivers Amatera Infostealer
HIGH
Malware

WordlistLoader Evades Detection, Delivers Amatera Infostealer

WordlistLoader uses a novel text-based obfuscation to bypass security, deploying the Amatera infostealer in ClickFix-style campaigns, posing a significant threat.

Runtime Rebel Intel
4 min read · Aug 25, 2026
HIGH
Malware

AmnesiaStealer macOS Malware Hijacks Browser Sessions via Remote Control

AmnesiaStealer targets macOS users via ClickFix attacks, cloning Chromium profiles to enable live remote control of authenticated browser sessions.

Runtime Rebel Intel
4 min read · Aug 16, 2026
HIGH
Malware

ClickFix Attack Deploys macOS Infostealer for Crypto Theft

The ClickFix attack leverages a Go-based macOS infostealer to pilfer cryptocurrency, browser data, and Apple Keychain credentials via a Bash script loader.

Runtime Rebel Intel
5 min read · Aug 7, 2026
Rogue AI Agents and Check Point Exploits: A Weekly Security Analysis
HIGH
Threat Intel

Rogue AI Agents and Check Point Exploits: A Weekly Security Analysis

Analysis of OpenAI's rogue AI agents, active Check Point VPN exploitation, and the emergence of Slopsquatting and ClickFix phishing lures in the wild.

Runtime Rebel Intel
3 min read · Jul 27, 2026

Advertisement

MEDIUM
Threat Intel

Steam Forum ClickFix Attacks Distribute XMRig Cryptominers

Attackers exploit Steam forums using ClickFix social engineering to trick gamers into installing XMRig cryptominers via malicious PowerShell commands.

Runtime Rebel Intel
4 min read · Jul 26, 2026
BlueNoroff Zoom Phishing Kit Targets Crypto Wallets
HIGH
Threat Intel

BlueNoroff Zoom Phishing Kit Targets Crypto Wallets

BlueNoroff uses a custom phishing kit to profile crypto wallets before delivering malware through impersonated Zoom and Microsoft Teams platforms.

Runtime Rebel Intel
4 min read · Jul 24, 2026
UAC-0145 ClickFix Strategy: How Sandworm Targets Ukraine with Malware
HIGH
Threat Intel

UAC-0145 ClickFix Strategy: How Sandworm Targets Ukraine with Malware

Russian threat actor UAC-0145 uses deceptive ClickFix CAPTCHAs to deliver data-stealing malware to Ukrainian targets. Learn how to detect and mitigate these TTPs.

Runtime Rebel Intel
4 min read · Jul 19, 2026
TELEPUZ Malware: Analyzing Modular Payloads in ClickFix Campaigns
HIGH
Malware

TELEPUZ Malware: Analyzing Modular Payloads in ClickFix Campaigns

TELEPUZ is a new modular malware spreading via ClickFix lures to steal sensitive data and execute remote commands on compromised Windows systems.

Runtime Rebel Intel
4 min read · Jul 16, 2026
ClickFix Ecosystem: Evasive Attack-as-a-Service & YARA Detection
HIGH
Threat Intel

ClickFix Ecosystem: Evasive Attack-as-a-Service & YARA Detection

The ClickFix ecosystem offers rented, evasive attack vectors bypassing AV/EDR. Learn why YARA analysis is crucial for detecting this scalable threat.

Runtime Rebel Intel
4 min read · Jul 14, 2026
SCMBANKER Malware: Analyzing ClickFix Lures Targeting Mexican Banks
HIGH
Malware

SCMBANKER Malware: Analyzing ClickFix Lures Targeting Mexican Banks

Elastic Security Labs tracks REF6045, deploying SCMBANKER malware via fake ClickFix CAPTCHA pages to compromise Mexican banking users.

Runtime Rebel Intel
4 min read · Jul 8, 2026
ClickFix Social Engineering: How to Detect Fake Browser Update Attacks
HIGH
Threat Intel

ClickFix Social Engineering: How to Detect Fake Browser Update Attacks

ClickFix has become the dominant malware delivery method. Learn how attackers use fake browser error overlays to trick users into executing malicious PowerShell.

Runtime Rebel Intel
3 min read · Jul 2, 2026
ClickFix Campaigns Expand Delivery with New Loaders and Fake Lures
HIGH
Threat Intel

ClickFix Campaigns Expand Delivery with New Loaders and Fake Lures

ClickFix campaigns are now deploying BabaDeda, Lorem Ipsum, and Potemkin loaders through fake browser update social engineering lures.

Runtime Rebel Intel
4 min read · Jun 16, 2026
Cyber Insurance Market Shifts: Rates Drop, Exclusions Widen
INFO
Threat Intel

Cyber Insurance Market Shifts: Rates Drop, Exclusions Widen

Organizations face reduced cyber insurance coverage despite dropping rates. Exclusions for social engineering attacks like ClickFix are widening, demanding policy…

Runtime Rebel Intel
5 min read · Jun 3, 2026
DriveSurge: Hijacking Thousands of Sites for ClickFix, FakeUpdate Malware
HIGH
Threat Intel

DriveSurge: Hijacking Thousands of Sites for ClickFix, FakeUpdate Malware

DriveSurge, a wide-scale IAB operation, hijacks thousands of trusted websites using a malicious TDS, redirecting users to sites distributing ClickFix and FakeUpdate…

Runtime Rebel Intel
4 min read · Jun 2, 2026
HIGH
Threat Intel

DriveSurge Campaigns: Detecting ClickFix and FakeUpdate Overlays

DriveSurge threat actors have hijacked thousands of sites to deploy ClickFix and FakeUpdate overlays, delivering info-stealers via deceptive browser alerts.

Runtime Rebel Intel
3 min read · Jun 2, 2026
CVE-2026-26980: Ghost CMS SQL Injection Leads to ClickFix Attacks
CRITICAL
Vulnerabilities

CVE-2026-26980: Ghost CMS SQL Injection Leads to ClickFix Attacks

Attackers exploit CVE-2026-26980 in Ghost CMS to compromise 700+ websites, deploying ClickFix malware that tricks users into executing malicious scripts.

Runtime Rebel Intel
4 min read · May 25, 2026
HIGH
Vulnerabilities

CVE-2025-26980: Ghost CMS SQL Injection Exploited in ClickFix Campaign

A critical SQL injection vulnerability in Ghost CMS (CVE-2025-26980) is being exploited to deliver ClickFix malware through malicious JavaScript injections.

Runtime Rebel Intel
3 min read · May 24, 2026
HIGH
Threat Intel

ClickFix Attacks Distribute Vidar Stealer: ACSC Warning & Mitigation

The ACSC warns Australian organizations of active ClickFix social engineering attacks deploying Vidar Stealer malware, risking data theft. Learn detection and mitigation.

Runtime Rebel Intel
4 min read · May 7, 2026
Sapphire Sleet's ClickFix: North Korea Targets macOS Users
HIGH
Threat Intel

Sapphire Sleet's ClickFix: North Korea Targets macOS Users

North Korea-backed Sapphire Sleet is deploying ClickFix malware via fake job offers and phony Zoom updates to steal macOS user credentials and data.

Runtime Rebel Intel
4 min read · Apr 16, 2026
HIGH
Malware

DeepLoad Malware: Analysis of ClickFix Attacks and Mitigation

DeepLoad malware, observed in ClickFix attacks, steals credentials, installs malicious browser extensions, and propagates via USB drives.

Runtime Rebel Intel
4 min read · Apr 1, 2026
DeepLoad Malware Leverages ClickFix, WMI for Browser Credential Theft
HIGH
Malware

DeepLoad Malware Leverages ClickFix, WMI for Browser Credential Theft

DeepLoad malware leverages ClickFix social engineering and WMI for persistence to steal browser credentials, employing AI-assisted obfuscation for evasion.

Runtime Rebel Intel
5 min read · Mar 30, 2026
MEDIUM
Threat Intel

macOS Terminal ClickFix Protections: Blocking Malicious Shell Commands

Apple introduces Terminal warnings in macOS Sequoia 15.2 to combat ClickFix social engineering attacks that trick users into executing malicious shell scripts.

Runtime Rebel Intel
3 min read · Mar 30, 2026