Skip to main content
← All Articles

Tag

#ClickFix

35 articles

Advertisement

HIGH
Malware

Infinity Stealer macOS Malware: Analyzing ClickFix Lures and Payloads

Infinity Stealer targets macOS via ClickFix social engineering. Learn how this Nuitka-compiled malware steals browser data, crypto wallets, and Keychain info.

Runtime Rebel Intel
3 min read · Mar 28, 2026
HIGH
Threat Intel

ClickFix Social Engineering Drops Infiniti Stealer on macOS

Attackers use fake Cloudflare CAPTCHA pages and ClickFix tactics to deliver the Python-based Infiniti Stealer to macOS systems via terminal commands.

Runtime Rebel Intel
4 min read · Mar 28, 2026
ClickFix Social Engineering Clusters Target Windows and macOS Systems
MEDIUM
Threat Intel

ClickFix Social Engineering Clusters Target Windows and macOS Systems

Insikt Group identifies five ClickFix clusters using obfuscated commands to exploit native system tools via fake browser error overlays on Windows and macOS.

Runtime Rebel Intel
4 min read · Mar 25, 2026
LeakNet Ransomware: ClickFix Exploitation and Deno Loader Analysis
MEDIUM
Malware

LeakNet Ransomware: ClickFix Exploitation and Deno Loader Analysis

LeakNet ransomware leverages ClickFix social engineering and Deno-based in-memory loaders to bypass traditional security controls and deploy payloads.

Runtime Rebel Intel
4 min read · Mar 17, 2026
MEDIUM
Threat Intel

LeakNet Ransomware: Stealthy Exploitation via Deno and ClickFix

LeakNet ransomware adopts ClickFix social engineering and the Deno runtime for stealthy initial access and loader deployment in corporate environments.

Runtime Rebel Intel
4 min read · Mar 17, 2026
ClickFix Campaigns Deliver MacSync macOS Infostealer via Fake AI Tools
HIGH
Threat Intel

ClickFix Campaigns Deliver MacSync macOS Infostealer via Fake AI Tools

Threat actors use ClickFix social engineering tactics to deploy the MacSync infostealer on macOS systems via fraudulent AI software installers.

Runtime Rebel Intel
4 min read · Mar 16, 2026

Advertisement

HIGH
Malware

SmartApeSG Leverages ClickFix Pages to Deploy Remcos RAT

Analysis of the SmartApeSG campaign, detailing its use of deceptive 'ClickFix' pages to distribute Remcos RAT.

Runtime Rebel Intel
4 min read · Mar 14, 2026
HIGH
Threat Intel

ClickFix Attack: Windows Terminal Used for Detection Evasion

The ClickFix attack leverages fake CAPTCHA pages to trick users into pasting malicious commands into Windows Terminal, bypassing traditional detection methods.

Runtime Rebel Intel
4 min read · Mar 9, 2026
HIGH
Threat Intel

Velvet Tempest Deploys Termite Ransomware via ClickFix and CastleRAT

Velvet Tempest leverages ClickFix social engineering and CastleRAT to deploy Termite ransomware, using legitimate Windows tools for stealthy execution.

Runtime Rebel Intel
4 min read · Mar 7, 2026
Windows Terminal Exploited in ClickFix Campaign for Lumma Stealer
HIGH
Threat Intel

Windows Terminal Exploited in ClickFix Campaign for Lumma Stealer

Microsoft identifies a new ClickFix campaign using Windows Terminal to deliver Lumma Stealer. Analysis of social engineering TTPs and mitigation steps included.

Runtime Rebel Intel
4 min read · Mar 6, 2026
HIGH
Malware

QuickLens Chrome Extension Hijacked to Deploy ClickFix Malware

Malicious QuickLens Chrome extension removed from Web Store after stealing cryptocurrency and deploying ClickFix malware to 30,000 users.

Runtime Rebel Intel
3 min read · Feb 28, 2026