<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #ClickFix</title><description>Cybersecurity articles tagged #ClickFix on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Node.js Abuse: Attackers Deploy Malware via Trusted Runtime</title><link>https://runtimerebel.com/blog/node-js-abuse-attackers-deploy-malware-via-trusted-runtime</link><guid isPermaLink="true">https://runtimerebel.com/blog/node-js-abuse-attackers-deploy-malware-via-trusted-runtime</guid><description>Threat actors are leveraging Node.js as a signed, trusted tool to deploy various malicious payloads, evading detection in targeted attacks since February 2026.</description><pubDate>Thu, 03 Sep 2026 12:22:47 GMT</pubDate><category>Node Js</category><category>Malware Delivery</category><category>ClickFix</category><category>Living-off-the-Land</category><category>EtherHiding</category></item><item><title>ClickFix Campaign Exploits Polygon Blockchain for C2 Evasion</title><link>https://runtimerebel.com/blog/clickfix-campaign-exploits-polygon-blockchain-for-c2-evasion</link><guid isPermaLink="true">https://runtimerebel.com/blog/clickfix-campaign-exploits-polygon-blockchain-for-c2-evasion</guid><description>The ClickFix campaign compromises 31 organizations, dynamically updating its C2 server via EtherHiding and the Polygon blockchain.</description><pubDate>Tue, 01 Sep 2026 19:01:53 GMT</pubDate><category>ClickFix</category><category>C2 Evasion</category><category>Ad Fraud</category><category>EtherHiding</category><category>Polygon Blockchain</category></item><item><title>WordlistLoader Evades Detection, Delivers Amatera Infostealer</title><link>https://runtimerebel.com/blog/wordlistloader-evades-detection-delivers-amatera-infostealer</link><guid isPermaLink="true">https://runtimerebel.com/blog/wordlistloader-evades-detection-delivers-amatera-infostealer</guid><description>WordlistLoader uses a novel text-based obfuscation to bypass security, deploying the Amatera infostealer in ClickFix-style campaigns, posing a significant threat.</description><pubDate>Tue, 25 Aug 2026 08:33:21 GMT</pubDate><category>Infostealer</category><category>Malware</category><category>Obfuscation</category><category>ClickFix</category><category>WordlistLoader</category></item><item><title>AmnesiaStealer macOS Malware Hijacks Browser Sessions via Remote Control</title><link>https://runtimerebel.com/blog/amnesiastealer-macos-malware-hijacks-browser-sessions-via-remote-control</link><guid isPermaLink="true">https://runtimerebel.com/blog/amnesiastealer-macos-malware-hijacks-browser-sessions-via-remote-control</guid><description>AmnesiaStealer targets macOS users via ClickFix attacks, cloning Chromium profiles to enable live remote control of authenticated browser sessions.</description><pubDate>Sun, 16 Aug 2026 16:14:35 GMT</pubDate><category>macOS</category><category>Infostealer</category><category>ClickFix</category><category>Chromium</category><category>AmnesiaStealer</category></item><item><title>ClickFix Attack Deploys macOS Infostealer for Crypto Theft</title><link>https://runtimerebel.com/blog/clickfix-attack-deploys-macos-infostealer-for-crypto-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/clickfix-attack-deploys-macos-infostealer-for-crypto-theft</guid><description>The ClickFix attack leverages a Go-based macOS infostealer to pilfer cryptocurrency, browser data, and Apple Keychain credentials via a Bash script loader.</description><pubDate>Fri, 07 Aug 2026 02:08:44 GMT</pubDate><category>ClickFix</category><category>macOS</category><category>Infostealer</category><category>Cryptocurrency</category><category>Golang</category></item><item><title>Rogue AI Agents and Check Point Exploits: A Weekly Security Analysis</title><link>https://runtimerebel.com/blog/rogue-ai-agents-and-check-point-exploits-a-weekly-security-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/rogue-ai-agents-and-check-point-exploits-a-weekly-security-analysis</guid><description>Analysis of OpenAI&apos;s rogue AI agents, active Check Point VPN exploitation, and the emergence of Slopsquatting and ClickFix phishing lures in the wild.</description><pubDate>Mon, 27 Jul 2026 14:37:58 GMT</pubDate><category>OpenAI</category><category>Check Point</category><category>ClickFix</category><category>Slopsquatting</category><category>CVE-2024-24919</category></item><item><title>Steam Forum ClickFix Attacks Distribute XMRig Cryptominers</title><link>https://runtimerebel.com/blog/steam-forum-clickfix-attacks-distribute-xmrig-cryptominers</link><guid isPermaLink="true">https://runtimerebel.com/blog/steam-forum-clickfix-attacks-distribute-xmrig-cryptominers</guid><description>Attackers exploit Steam forums using ClickFix social engineering to trick gamers into installing XMRig cryptominers via malicious PowerShell commands.</description><pubDate>Sun, 26 Jul 2026 02:54:23 GMT</pubDate><category>Steam</category><category>ClickFix</category><category>XMRig</category><category>Social Engineering</category><category>Cryptomining</category></item><item><title>BlueNoroff Zoom Phishing Kit Targets Crypto Wallets</title><link>https://runtimerebel.com/blog/bluenoroff-zoom-phishing-kit-targets-crypto-wallets</link><guid isPermaLink="true">https://runtimerebel.com/blog/bluenoroff-zoom-phishing-kit-targets-crypto-wallets</guid><description>BlueNoroff uses a custom phishing kit to profile crypto wallets before delivering malware through impersonated Zoom and Microsoft Teams platforms.</description><pubDate>Fri, 24 Jul 2026 17:39:06 GMT</pubDate><category>BlueNoroff</category><category>Lazarus Group</category><category>Cryptocurrency Theft</category><category>ClickFix</category><category>Phishing</category></item><item><title>UAC-0145 ClickFix Strategy: How Sandworm Targets Ukraine with Malware</title><link>https://runtimerebel.com/blog/uac-0145-clickfix-strategy-how-sandworm-targets-ukraine-with-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/uac-0145-clickfix-strategy-how-sandworm-targets-ukraine-with-malware</guid><description>Russian threat actor UAC-0145 uses deceptive ClickFix CAPTCHAs to deliver data-stealing malware to Ukrainian targets. Learn how to detect and mitigate these TTPs.</description><pubDate>Sun, 19 Jul 2026 16:59:50 GMT</pubDate><category>UAC 0145</category><category>Sandworm</category><category>ClickFix</category><category>Ukraine</category><category>Malware</category><category>Phishing</category></item><item><title>TELEPUZ Malware: Analyzing Modular Payloads in ClickFix Campaigns</title><link>https://runtimerebel.com/blog/telepuz-malware-analyzing-modular-payloads-in-clickfix-campaigns</link><guid isPermaLink="true">https://runtimerebel.com/blog/telepuz-malware-analyzing-modular-payloads-in-clickfix-campaigns</guid><description>TELEPUZ is a new modular malware spreading via ClickFix lures to steal sensitive data and execute remote commands on compromised Windows systems.</description><pubDate>Thu, 16 Jul 2026 14:00:24 GMT</pubDate><category>TELEPUZ</category><category>ClickFix</category><category>Social Engineering</category><category>Elastic Security Labs</category><category>Data Stealer</category></item><item><title>ClickFix Ecosystem: Evasive Attack-as-a-Service &amp; YARA Detection</title><link>https://runtimerebel.com/blog/clickfix-ecosystem-evasive-attack-as-a-service-yara-detection</link><guid isPermaLink="true">https://runtimerebel.com/blog/clickfix-ecosystem-evasive-attack-as-a-service-yara-detection</guid><description>The ClickFix ecosystem offers rented, evasive attack vectors bypassing AV/EDR. Learn why YARA analysis is crucial for detecting this scalable threat.</description><pubDate>Tue, 14 Jul 2026 17:24:10 GMT</pubDate><category>ClickFix</category><category>Attack as a Service</category><category>Evasion</category><category>AV Bypass</category><category>EDR Bypass</category><category>YARA Detection</category></item><item><title>SCMBANKER Malware: Analyzing ClickFix Lures Targeting Mexican Banks</title><link>https://runtimerebel.com/blog/scmbanker-malware-analyzing-clickfix-lures-targeting-mexican-banks</link><guid isPermaLink="true">https://runtimerebel.com/blog/scmbanker-malware-analyzing-clickfix-lures-targeting-mexican-banks</guid><description>Elastic Security Labs tracks REF6045, deploying SCMBANKER malware via fake ClickFix CAPTCHA pages to compromise Mexican banking users.</description><pubDate>Wed, 08 Jul 2026 14:14:47 GMT</pubDate><category>SCMBANKER</category><category>REF6045</category><category>Banking Trojan</category><category>Mexico</category><category>ClickFix</category><category>Phishing</category></item><item><title>ClickFix Social Engineering: How to Detect Fake Browser Update Attacks</title><link>https://runtimerebel.com/blog/clickfix-social-engineering-how-to-detect-fake-browser-update-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/clickfix-social-engineering-how-to-detect-fake-browser-update-attacks</guid><description>ClickFix has become the dominant malware delivery method. Learn how attackers use fake browser error overlays to trick users into executing malicious PowerShell.</description><pubDate>Thu, 02 Jul 2026 07:39:48 GMT</pubDate><category>ClickFix</category><category>Social Engineering</category><category>Lumma Stealer</category><category>Initial Access</category><category>ClearFake</category></item><item><title>ClickFix Campaigns Expand Delivery with New Loaders and Fake Lures</title><link>https://runtimerebel.com/blog/clickfix-campaigns-expand-delivery-with-new-loaders-and-fake-lures</link><guid isPermaLink="true">https://runtimerebel.com/blog/clickfix-campaigns-expand-delivery-with-new-loaders-and-fake-lures</guid><description>ClickFix campaigns are now deploying BabaDeda, Lorem Ipsum, and Potemkin loaders through fake browser update social engineering lures.</description><pubDate>Tue, 16 Jun 2026 21:08:00 GMT</pubDate><category>ClickFix</category><category>BabaDeda</category><category>Lorem Ipsum Loader</category><category>Potemkin</category><category>Social Engineering</category></item><item><title>Cyber Insurance Market Shifts: Rates Drop, Exclusions Widen</title><link>https://runtimerebel.com/blog/cyber-insurance-market-shifts-rates-drop-exclusions-widen</link><guid isPermaLink="true">https://runtimerebel.com/blog/cyber-insurance-market-shifts-rates-drop-exclusions-widen</guid><description>Organizations face reduced cyber insurance coverage despite dropping rates. Exclusions for social engineering attacks like ClickFix are widening, demanding policy…</description><pubDate>Wed, 03 Jun 2026 21:12:02 GMT</pubDate><category>Cyber Insurance</category><category>Social Engineering</category><category>Risk Management</category><category>Policy Exclusions</category><category>ClickFix</category></item><item><title>DriveSurge: Hijacking Thousands of Sites for ClickFix, FakeUpdate Malware</title><link>https://runtimerebel.com/blog/drivesurge-hijacking-thousands-of-sites-for-clickfix-fakeupdate-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/drivesurge-hijacking-thousands-of-sites-for-clickfix-fakeupdate-malware</guid><description>DriveSurge, a wide-scale IAB operation, hijacks thousands of trusted websites using a malicious TDS, redirecting users to sites distributing ClickFix and FakeUpdate…</description><pubDate>Tue, 02 Jun 2026 21:11:42 GMT</pubDate><category>DriveSurge</category><category>TDS</category><category>ClickFix</category><category>FakeUpdate</category><category>SocGholish</category><category>Malvertising</category><category>Ad Hijacking</category></item><item><title>DriveSurge Campaigns: Detecting ClickFix and FakeUpdate Overlays</title><link>https://runtimerebel.com/blog/drivesurge-campaigns-detecting-clickfix-and-fakeupdate-overlays</link><guid isPermaLink="true">https://runtimerebel.com/blog/drivesurge-campaigns-detecting-clickfix-and-fakeupdate-overlays</guid><description>DriveSurge threat actors have hijacked thousands of sites to deploy ClickFix and FakeUpdate overlays, delivering info-stealers via deceptive browser alerts.</description><pubDate>Tue, 02 Jun 2026 01:03:09 GMT</pubDate><category>DriveSurge</category><category>ClickFix</category><category>Fake Updates</category><category>SocGholish</category><category>WordPress Security</category><category>Lumma Stealer</category><category>AsyncRAT</category></item><item><title>CVE-2026-26980: Ghost CMS SQL Injection Leads to ClickFix Attacks</title><link>https://runtimerebel.com/blog/cve-2026-26980-ghost-cms-sql-injection-leads-to-clickfix-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-26980-ghost-cms-sql-injection-leads-to-clickfix-attacks</guid><description>Attackers exploit CVE-2026-26980 in Ghost CMS to compromise 700+ websites, deploying ClickFix malware that tricks users into executing malicious scripts.</description><pubDate>Mon, 25 May 2026 13:16:58 GMT</pubDate><category>CVE-2026-26980</category><category>Ghost CMS</category><category>SQL Injection</category><category>ClickFix</category><category>Malware</category></item><item><title>CVE-2025-26980: Ghost CMS SQL Injection Exploited in ClickFix Campaign</title><link>https://runtimerebel.com/blog/cve-2025-26980-ghost-cms-sql-injection-exploited-in-clickfix-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-26980-ghost-cms-sql-injection-exploited-in-clickfix-campaign</guid><description>A critical SQL injection vulnerability in Ghost CMS (CVE-2025-26980) is being exploited to deliver ClickFix malware through malicious JavaScript injections.</description><pubDate>Sun, 24 May 2026 16:26:15 GMT</pubDate><category>Ghost CMS</category><category>CVE-2025-26980</category><category>SQL Injection</category><category>ClickFix</category><category>Malware Campaign</category></item><item><title>ClickFix Attacks Distribute Vidar Stealer: ACSC Warning &amp; Mitigation</title><link>https://runtimerebel.com/blog/clickfix-attacks-distribute-vidar-stealer-acsc-warning-mitigation</link><guid isPermaLink="true">https://runtimerebel.com/blog/clickfix-attacks-distribute-vidar-stealer-acsc-warning-mitigation</guid><description>The ACSC warns Australian organizations of active ClickFix social engineering attacks deploying Vidar Stealer malware, risking data theft. Learn detection and mitigation.</description><pubDate>Thu, 07 May 2026 20:33:35 GMT</pubDate><category>Vidar Stealer</category><category>ClickFix</category><category>Social Engineering</category><category>ACSC</category><category>Infostealer</category><category>Australia</category></item><item><title>Sapphire Sleet&apos;s ClickFix: North Korea Targets macOS Users</title><link>https://runtimerebel.com/blog/sapphire-sleet-s-clickfix-north-korea-targets-macos-users</link><guid isPermaLink="true">https://runtimerebel.com/blog/sapphire-sleet-s-clickfix-north-korea-targets-macos-users</guid><description>North Korea-backed Sapphire Sleet is deploying ClickFix malware via fake job offers and phony Zoom updates to steal macOS user credentials and data.</description><pubDate>Thu, 16 Apr 2026 20:22:49 GMT</pubDate><category>Sapphire Sleet</category><category>ClickFix</category><category>macOS</category><category>North Korea</category><category>Phishing</category><category>Data Theft</category><category>APT</category></item><item><title>DeepLoad Malware: Analysis of ClickFix Attacks and Mitigation</title><link>https://runtimerebel.com/blog/deepload-malware-analysis-of-clickfix-attacks-and-mitigation</link><guid isPermaLink="true">https://runtimerebel.com/blog/deepload-malware-analysis-of-clickfix-attacks-and-mitigation</guid><description>DeepLoad malware, observed in ClickFix attacks, steals credentials, installs malicious browser extensions, and propagates via USB drives.</description><pubDate>Wed, 01 Apr 2026 16:27:41 GMT</pubDate><category>DeepLoad</category><category>ClickFix</category><category>Malware</category><category>Credential Theft</category><category>USB Spreading</category><category>Browser Extension</category></item><item><title>DeepLoad Malware Leverages ClickFix, WMI for Browser Credential Theft</title><link>https://runtimerebel.com/blog/deepload-malware-leverages-clickfix-wmi-for-browser-credential-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/deepload-malware-leverages-clickfix-wmi-for-browser-credential-theft</guid><description>DeepLoad malware leverages ClickFix social engineering and WMI for persistence to steal browser credentials, employing AI-assisted obfuscation for evasion.</description><pubDate>Mon, 30 Mar 2026 20:18:04 GMT</pubDate><category>DeepLoad</category><category>ClickFix</category><category>WMI</category><category>Credential Theft</category><category>Malware Loader</category><category>Browser Security</category><category>Social Engineering</category></item><item><title>macOS Terminal ClickFix Protections: Blocking Malicious Shell Commands</title><link>https://runtimerebel.com/blog/macos-terminal-clickfix-protections-blocking-malicious-shell-commands</link><guid isPermaLink="true">https://runtimerebel.com/blog/macos-terminal-clickfix-protections-blocking-malicious-shell-commands</guid><description>Apple introduces Terminal warnings in macOS Sequoia 15.2 to combat ClickFix social engineering attacks that trick users into executing malicious shell scripts.</description><pubDate>Mon, 30 Mar 2026 16:28:10 GMT</pubDate><category>macOS</category><category>Sequoia</category><category>ClickFix</category><category>Social Engineering</category><category>Terminal</category><category>Malware</category></item><item><title>Infinity Stealer macOS Malware: Analyzing ClickFix Lures and Payloads</title><link>https://runtimerebel.com/blog/infinity-stealer-macos-malware-analyzing-clickfix-lures-and-payloads</link><guid isPermaLink="true">https://runtimerebel.com/blog/infinity-stealer-macos-malware-analyzing-clickfix-lures-and-payloads</guid><description>Infinity Stealer targets macOS via ClickFix social engineering. Learn how this Nuitka-compiled malware steals browser data, crypto wallets, and Keychain info.</description><pubDate>Sat, 28 Mar 2026 16:13:39 GMT</pubDate><category>macOS</category><category>Infinity Stealer</category><category>Infostealer</category><category>Nuitka</category><category>ClickFix</category><category>Social Engineering</category></item><item><title>ClickFix Social Engineering Drops Infiniti Stealer on macOS</title><link>https://runtimerebel.com/blog/clickfix-social-engineering-drops-infiniti-stealer-on-macos</link><guid isPermaLink="true">https://runtimerebel.com/blog/clickfix-social-engineering-drops-infiniti-stealer-on-macos</guid><description>Attackers use fake Cloudflare CAPTCHA pages and ClickFix tactics to deliver the Python-based Infiniti Stealer to macOS systems via terminal commands.</description><pubDate>Sat, 28 Mar 2026 12:21:09 GMT</pubDate><category>macOS</category><category>Infiniti Stealer</category><category>ClickFix</category><category>Social Engineering</category><category>Cloudflare Lures</category></item><item><title>ClickFix Social Engineering Clusters Target Windows and macOS Systems</title><link>https://runtimerebel.com/blog/clickfix-social-engineering-clusters-target-windows-and-macos-systems</link><guid isPermaLink="true">https://runtimerebel.com/blog/clickfix-social-engineering-clusters-target-windows-and-macos-systems</guid><description>Insikt Group identifies five ClickFix clusters using obfuscated commands to exploit native system tools via fake browser error overlays on Windows and macOS.</description><pubDate>Wed, 25 Mar 2026 12:25:41 GMT</pubDate><category>ClickFix</category><category>Social Engineering</category><category>macOS Security</category><category>Powershell Obfuscation</category><category>Initial Access</category></item><item><title>LeakNet Ransomware: ClickFix Exploitation and Deno Loader Analysis</title><link>https://runtimerebel.com/blog/leaknet-ransomware-clickfix-exploitation-and-deno-loader-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/leaknet-ransomware-clickfix-exploitation-and-deno-loader-analysis</guid><description>LeakNet ransomware leverages ClickFix social engineering and Deno-based in-memory loaders to bypass traditional security controls and deploy payloads.</description><pubDate>Tue, 17 Mar 2026 16:29:47 GMT</pubDate><category>Leaknet</category><category>ClickFix</category><category>Deno Runtime</category><category>Ransomware</category><category>Social Engineering</category></item><item><title>LeakNet Ransomware: Stealthy Exploitation via Deno and ClickFix</title><link>https://runtimerebel.com/blog/leaknet-ransomware-stealthy-exploitation-via-deno-and-clickfix</link><guid isPermaLink="true">https://runtimerebel.com/blog/leaknet-ransomware-stealthy-exploitation-via-deno-and-clickfix</guid><description>LeakNet ransomware adopts ClickFix social engineering and the Deno runtime for stealthy initial access and loader deployment in corporate environments.</description><pubDate>Tue, 17 Mar 2026 12:30:38 GMT</pubDate><category>Leaknet</category><category>ClickFix</category><category>Deno Runtime</category><category>Ransomware</category><category>Social Engineering</category></item><item><title>ClickFix Campaigns Deliver MacSync macOS Infostealer via Fake AI Tools</title><link>https://runtimerebel.com/blog/clickfix-campaigns-deliver-macsync-macos-infostealer-via-fake-ai-tools</link><guid isPermaLink="true">https://runtimerebel.com/blog/clickfix-campaigns-deliver-macsync-macos-infostealer-via-fake-ai-tools</guid><description>Threat actors use ClickFix social engineering tactics to deploy the MacSync infostealer on macOS systems via fraudulent AI software installers.</description><pubDate>Mon, 16 Mar 2026 12:24:32 GMT</pubDate><category>Macsync</category><category>ClickFix</category><category>macOS</category><category>Infostealer</category><category>Social Engineering</category></item><item><title>SmartApeSG Leverages ClickFix Pages to Deploy Remcos RAT</title><link>https://runtimerebel.com/blog/smartapesg-leverages-clickfix-pages-to-deploy-remcos-rat</link><guid isPermaLink="true">https://runtimerebel.com/blog/smartapesg-leverages-clickfix-pages-to-deploy-remcos-rat</guid><description>Analysis of the SmartApeSG campaign, detailing its use of deceptive &apos;ClickFix&apos; pages to distribute Remcos RAT.</description><pubDate>Sat, 14 Mar 2026 04:37:52 GMT</pubDate><category>SmartApeSG</category><category>Remcos RAT</category><category>ClickFix</category><category>RAT</category><category>Phishing</category></item><item><title>ClickFix Attack: Windows Terminal Used for Detection Evasion</title><link>https://runtimerebel.com/blog/clickfix-attack-windows-terminal-used-for-detection-evasion</link><guid isPermaLink="true">https://runtimerebel.com/blog/clickfix-attack-windows-terminal-used-for-detection-evasion</guid><description>The ClickFix attack leverages fake CAPTCHA pages to trick users into pasting malicious commands into Windows Terminal, bypassing traditional detection methods.</description><pubDate>Mon, 09 Mar 2026 16:34:31 GMT</pubDate><category>ClickFix</category><category>Windows Terminal</category><category>Evasion</category><category>Phishing</category><category>Social Engineering</category><category>Command Execution</category></item><item><title>Velvet Tempest Deploys Termite Ransomware via ClickFix and CastleRAT</title><link>https://runtimerebel.com/blog/velvet-tempest-deploys-termite-ransomware-via-clickfix-and-castlerat</link><guid isPermaLink="true">https://runtimerebel.com/blog/velvet-tempest-deploys-termite-ransomware-via-clickfix-and-castlerat</guid><description>Velvet Tempest leverages ClickFix social engineering and CastleRAT to deploy Termite ransomware, using legitimate Windows tools for stealthy execution.</description><pubDate>Sat, 07 Mar 2026 20:09:53 GMT</pubDate><category>Velvet Tempest</category><category>CastleRAT</category><category>Termite Ransomware</category><category>ClickFix</category><category>DonutLoader</category><category>Social Engineering</category></item><item><title>Windows Terminal Exploited in ClickFix Campaign for Lumma Stealer</title><link>https://runtimerebel.com/blog/windows-terminal-exploited-in-clickfix-campaign-for-lumma-stealer</link><guid isPermaLink="true">https://runtimerebel.com/blog/windows-terminal-exploited-in-clickfix-campaign-for-lumma-stealer</guid><description>Microsoft identifies a new ClickFix campaign using Windows Terminal to deliver Lumma Stealer. Analysis of social engineering TTPs and mitigation steps included.</description><pubDate>Fri, 06 Mar 2026 08:14:22 GMT</pubDate><category>ClickFix</category><category>Lumma Stealer</category><category>Windows Terminal</category><category>Social Engineering</category><category>Microsoft</category></item><item><title>QuickLens Chrome Extension Hijacked to Deploy ClickFix Malware</title><link>https://runtimerebel.com/blog/quicklens-chrome-extension-hijacked-to-deploy-clickfix-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/quicklens-chrome-extension-hijacked-to-deploy-clickfix-malware</guid><description>Malicious QuickLens Chrome extension removed from Web Store after stealing cryptocurrency and deploying ClickFix malware to 30,000 users.</description><pubDate>Sat, 28 Feb 2026 20:09:10 GMT</pubDate><category>QuickLens</category><category>ClickFix</category><category>Chrome Extension</category><category>Credential Theft</category><category>Cryptocurrency</category></item></channel></rss>