Skip to main content

Threats Tagged 'clickfix'

View all threats tagged with 'clickfix'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: clickfix

Threats Tagged 'clickfix'

Click on any threat for detailed analysis and mitigation recommendations

Blackpoint's Adversary Pursuit Group identified ChainScript, a previously unnamed Node.js remote access trojan discovered during ClickFix investigation. The malware disguises itself as legitimate software including Spotify, Zoom Workplace, and Microsoft Teams through malicious Windows Installer packages. ChainScript employs an EtherHiding-style C2 discovery technique utilizing a Polygon smart contract to dynamically locate active WebSocket infrastructure, enabling operators to rotate backend services without rebuilding agents. The RAT provides comprehensive remote access capabilities including interactive shell sessions, file operations, screenshots, payload deployment, cryptocurrency wallet discovery, remote JavaScript execution, self-update mechanisms, and cleanup functions. Multiple builds appeared under different names (ComponentTask33, UpdateDigital, HostShared, OrchidViolet66) while maintaining consistent core agent architecture. Analysis revealed automated contract deployment integrated into the mal...

Join the discussion

A significant supply chain attack compromised Brevo's infrastructure on September 14, 2026, affecting over 100,000 customer websites. Attackers injected malicious code into Brevo's JavaScript assets and widgets, delivering two distinct payloads: a WordPress plugin backdoor automatically installed when site administrators visited their own sites while logged in, and ClickFix overlays targeting regular visitors. The attack vector involved modification of Brevo's CDN-hosted files and creation of malicious subdomains under sendibt1.com. Evidence suggests attackers gained access to Brevo's Cloudflare account, allowing them to modify DNS records and rewrite content dynamically. The malicious activity lasted approximately four hours, from 16:05 to 20:12 UTC. Brevo's prominent clients include eBay, Louis Vuitton, Michelin, and Amnesty International, amplifying the attack's potential impact significantly.

Join the discussion

VectraRAT is a previously undocumented Malware-as-a-Service platform combining a Go-based control server (VectraHub) with a native C++ Windows implant, renting from $250 monthly. The developer, operating under the handle 'Vectra' (formerly 'Nyxel'), has been active since August 2022 without prior public documentation. The platform offers hidden desktop control, keylogging, clipboard hijacking with cryptocurrency address replacement, browser credential theft, and a UAC bypass achieving elevation without user prompts. Delivered through Amadey loader and ClickFix campaigns targeting tax-themed lures, 48% of observed victims run corporate Windows editions including Windows Server 2025. Infrastructure analysis revealed exposed directories and operational panels across multiple hosting providers, with victims spanning the United States, Russia, Germany, and other nations.

Join the discussion

An analysis of Atomic macOS (AMOS) stealer infections from early August 2026 reveals this information stealer targeting macOS systems has been advertised since April 2024. AMOS exfiltrates system information, login credentials, and sensitive data from web browsers and cryptocurrency wallets. Distribution methods include ClickFix campaigns, malicious advertisements, and fake cracked software sites offering macOS toolkits. The examined infection chain begins with malicious instructions on getmacouscloud[.]com, leading to execution of a Zsh script that retrieves and installs Mach-O binaries establishing persistence in system directories. The malware collects data from various applications including Binance, TonKeeper, Telegram, AWS, Docker, and FileZilla, compressing it into an out.zip file before exfiltrating to command and control servers. Post-infection traffic consists of HTTP POST requests with specific stage parameters indicating collected data types. The malware demonstrates active development with con...

Join the discussion

LegionLoader malware is being distributed through ClickFix tactics using fake Cloudflare CAPTCHA pages. Two primary distribution methods have been identified: one exploits Korea's Newlywed Hope Town Namu Wiki page with malicious URLs, while the other uses spear phishing emails targeting specific companies disguised as internal business system account issuance instructions. When users access these malicious URLs, they are redirected to fake CAPTCHA pages that trick them into executing PowerShell commands, which download and execute LegionLoader. The malware sequentially decrypts encrypted shellcode and PE files, evaluates the infection environment through display device checks and ASN verification, then executes backdoor malware capable of running various payloads including PE files, shellcode, PowerShell scripts, and MSI files. It also steals Chrome browser credentials and profile information based on C2 server commands.

Join the discussion

In June 2026, a new malware family named SloppyRAT was identified, likely used by ransomware-related threat actors to establish footholds for lateral movement. Delivered through multi-stage ClickFix infection chains, the malware features encrypted code blocks, EtherHiding for command-and-control resolution via Polygon JSON-RPC protocol, and multiple anti-analysis techniques including junk code and indirect system calls. SloppyRAT implements certificate pinning to prevent TLS traffic inspection and includes 47 built-in PowerShell-like commands for remote access. The infection chain uses finger.exe, IronPython, and deploys CastleLoader and CastleRAT components before installing SloppyRAT. Despite sophisticated capabilities, the codebase contains numerous software bugs affecting persistence mechanisms and other features, suggesting active development.

Join the discussion

MacSync Stealer is a macOS information stealer and remote-access stager delivered through ClickFix social engineering and malvertising campaigns. Operating under a malware-as-a-service model, it employs sophisticated evasion techniques including process daemonization, single-byte XOR obfuscation, and in-memory AppleScript execution to bypass Apple Gatekeeper, XProtect, and EDR solutions. The malware exfiltrates credentials, browser data, cryptocurrency wallets, and SSH keys through fault-tolerant 10MB chunked uploads to command-and-control infrastructure. MacSync targets professionals in software engineering, cryptocurrency, fintech, and corporate environments across North America, Europe, and Asia-Pacific regions, with campaigns impersonating legitimate services like Google Meet, Claude AI, Docker, and TradingView to trick victims into executing malicious Terminal commands.

Join the discussion

Cisco Talos identified a malware infection chain involving WebDAV-based DLL execution delivering the Amatera stealer and secondary payloads including ZigCryptoStealer and NetSupport Manager. The infection chain uses a Cloudflare Worker to inject JavaScript stored on BNB Smart Chain and a fake CAPTCHA prompt to trick victims into executing the malware. Two distinct DLL loaders named "verification.google" and "pf.ch" were observed, each deploying different secondary payloads. The "verification.google" loader installed NetSupport Manager with a command-and-control server IP linked to Russia, suggesting a Russian threat actor. The infection was first observed in April 2026 targeting a Ukrainian government organization but is assessed as not specifically targeted. Multiple infection chains delivering Amatera stealer have been documented, but no direct infrastructure links were found between them. The threat involves credential and cryptocurrency theft through sophisticated multi-stage delivery mechanisms.

Join the discussion

The TerminalFix campaign is a sophisticated multi-stage intrusion targeting organizations via compromised websites that display fake Cloudflare CAPTCHA overlays. Victims are tricked into executing malicious PowerShell commands that download and execute a signed legitimate binary alongside a malicious DLL for sideloading. This leads to steganographic payload extraction, extensive Active Directory reconnaissance, and deployment of a Python-based reverse-tunnel implant providing persistent network-level proxy access. The campaign enables attackers to pivot within the network, conduct domain enumeration, and maintain stealthy persistent access. Although no direct downstream actions were observed, the access gained could facilitate privilege escalation, data exfiltration, and ransomware deployment. The campaign combines advanced evasion techniques and persistent network access, posing a serious threat to enterprise environments.

Join the discussion
0

A phishing campaign abuses npm package mirrors to host fake Cloudflare Captcha pages embedded in malicious npm packages. These pages are served via trusted mirror domains, increasing their credibility and facilitating phishing attacks such as ClickFix delivery. The campaign uses typosquatted domains and legitimate key-value storage services to redirect victims dynamically. Downloading the packages is not harmful, but accessing the HTML files through mirror URLs exposes users to phishing risks.

Join the discussion

Showing 1 to 10 of 102 results

Filters:Tag: clickfix
Page 1 of 11
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses