< ciso
brief />
Tag Banner

All news with #clickfix tag

106 articles

Placeholder domain abused to deliver ClickFix malware

🛡️ third-party[.]com is being used to deliver a ClickFix lure that targets Windows systems and sidesteps protections, Manifold Security reports. The site impersonates a Cloudflare “are you human?” check, poisons the clipboard and instructs users to paste a command that runs a remote PowerShell payload. Unlike reserved placeholders such as example.com, third-party[.]com was available for registration and was abused to trap unwary developers and enterprise users.
read more →

MacSync uses iCloud calendars to load payloads

📌 A new MacSync variant for macOS now leverages public iCloud calendar events to deliver follow-on payloads. Kaspersky found the Swift-based infostealer being distributed via ClickFix-style social engineering and fake apps, with a downloader extracting commands from calendar DESCRIPTION fields to fetch archives hosted on iCloud. The malware retains broad credential-stealing capabilities and added an Objective-C backdoor that persists via LaunchAgents, .zshrc changes, and Git hooks.
read more →

Placeholder domains weaponized to deliver ClickFix lures

🛡️ Manifold Security discovered that the documentation placeholder domain third-party[.]com has been registered and weaponized to serve a ClickFix social engineering lure for Windows visitors while showing benign decoys to others. The domain, referenced in over 1,700 public GitHub repositories, poisons the clipboard and prompts users to paste and run a command that fetches a remote PowerShell payload. It has been flagged as malicious on VirusTotal and Google Safe Browsing, and the researchers found a further 13 non-reserved placeholder domains being abused to serve scams and scareware to macOS users.
read more →

ClickFix campaign injects fake Cloudflare lures

🛡️ Arctic Wolf Labs and Blackpoint Cyber reported an active ClickFix campaign compromising Ukrainian business websites to serve bogus Cloudflare verification pages that trick victims into executing an MSI installer. The MSI chain delivers a newly observed information stealer called Psychedelic, which harvests browser credentials, tokens, and crypto-wallet data, sets persistence, and contacts a C2 for follow-on tasks. Researchers also linked the ClickFix chain to other payloads including RemotePanel and BoundSiphon, highlighting modular remote-access and data-theft capabilities and evidence pointing to likely Russian-speaking operators.
read more →

ClickFix: Emerging dominant initial-access vector

🛡️ ClickFix is now the leading initial-access technique in enterprise telemetry, operating without exploits, attachments, or downloads. The attack uses malicious pages that copy a command to the clipboard and instruct users to paste it into native system interpreters, evading conventional detectors. Its infrastructure leverages on-chain resolution and distributed resolvers to survive takedown, and payload delivery is fingerprint-gated to evade sandboxes. Effective defenses focus on constraining clipboard writes and forcing interpreters through authenticated proxies.
read more →

Placeholder domain abused to deliver ClickFix attacks

🛡️ The commonly used placeholder domain third-party.com is serving a fake Cloudflare verification page that attempts to trick Windows users into running PowerShell commands. The site copies a malicious command to the clipboard and instructs victims to paste and execute it, a technique known as ClickFix. Researchers found the domain referenced across public developer docs and confirmed the malicious behavior; the current payload host was not resolving during testing.
read more →

Exvicy ClickFix MaaS Reuses ErrTraffic Code

🛡️ A new ClickFix malware-as-a-service framework named Exvicy has been observed delivering malware via compromised WordPress sites by injecting obfuscated JavaScript and a fake Cloudflare Turnstile lure. Sekoia's Threat Detection & Research team linked Exvicy to active C2 infrastructure after telemetry showed customer hosts communicating with its servers. The actor advertises the service on Exploit.IN, with pricing rising from $1,200 to $2,000 per month and operational panels discovered through a screenshot in the advert. Sekoia assessed Exvicy reuses large portions of ErrTraffic's code, with the main technical difference being Exvicy's hardcoded C2 servers versus ErrTraffic's blockchain-based hiding.
read more →

ClickFix Lures Deploy ChainScript RAT via Decentralized C2

🛡️ Blackpoint APG researchers detail a campaign using ClickFix-style lures to deliver a new remote access trojan named ChainScript. The RAT, disguised under multiple build names and posing as legitimate apps like Spotify and Microsoft Teams, uses a Polygon smart contract for EtherHiding-style C2 discovery and communicates over WebSockets. ChainScript provides extensive remote capabilities including shell access, file ops, screenshots, wallet enumeration, and self-updating persistence via scheduled tasks and registry fallbacks.
read more →

Malicious browser extensions enable ClickFix attacks

🛡️ This post explains how browser extensions can be abused to deliver ClickFix social-engineering attacks, using a recent campaign that pushed 19 malicious add‑ons through official stores as an example. It describes how extensions gain wide permissions, how attackers acquire or buy extensions, and how updates and C2 modules let them inject malicious code into otherwise legitimate pages. The article highlights modules that steal credentials, drain crypto wallets, prompt for seed phrases, and serve ClickFix instructions that can break out of the browser and install system‑level malware.
read more →

Threat actors favor repeatable playbooks over novelty

🔍 Microsoft and Bitdefender telemetry show attackers increasingly rely on simple, repeatable methods such as ClickFix and living-off-the-land techniques rather than bespoke exploits. These approaches scale because they are platform-agnostic, require no new tooling, and reuse built-in binaries and publicly released exploits. The result is higher throughput of incidents with falling per-victim returns, incentivizing low-cost, repeatable campaigns.
read more →

TerminalFix campaign uses reverse-tunnel to pivot

🛡️ Microsoft Threat Intelligence details a TerminalFix campaign, a ClickFix variant that lures users with a fake Cloudflare Turnstile overlay and tricks them into pasting a malicious PowerShell command into Windows Terminal or PowerShell. The command drops a ZIP with a legitimate executable and a malicious DLL that is sideloaded, then uses steganography to extract further payloads from PNG images, establishes dual persistence, performs extensive Active Directory reconnaissance, and deploys a Python-based reverse-tunnel implant for SOCKS-style network access. The chain enables persistent, network-level proxy access and increases risk of lateral movement and data or credential theft.
read more →

AmnesiaStealer macOS malware hijacks browser sessions

🛡️ A new macOS infostealer called AmnesiaStealer uses ClickFix campaigns to deliver a Mach-O payload inside a password-protected archive. It copies Chromium profiles and launches hidden, headless browser instances to preserve authentication state while enabling remote operator control. The malware exfiltrates passwords, keychain items, crypto wallets, browser data across 16 Chromium-based browsers, and streams live screencasts and input via WebSocket channels. Researchers at Jamf warn the module abuses the Chrome DevTools Protocol to let attackers navigate and act in victims' authenticated sessions.
read more →

New macOS infostealer spreads via ClickFix lure

🛡️ Researchers at Jamf warn of a Rust-based macOS infostealer named AmnesiaStealer distributed through ClickFix social engineering. The malware harvests credentials, browser data and live sessions, uses OS version–specific bypasses, and includes a remote-controlled second stage to stealthily control Chromium-family browsers. Jamf recommends enabling threat prevention, advanced threat controls and web protection set to Block and Report.
read more →

ClickFix macOS infostealer targets crypto and credentials

🛡️ A Go-based malware delivered via a ClickFix campaign targets macOS users to steal cryptocurrency, browser passwords, Apple Keychain data, and cached credentials. Researchers at Huntress found the attack uses a Bash profiler and Mach-O payload tailored to the victim’s CPU, persists by faking errors with osascript, and removes quarantine flags to bypass Gatekeeper. The malware can intercept and divert crypto transactions and selectively drain a percentage of funds.
read more →

macOS ClickFix campaign uses browser fingerprinting

🛡️ Microsoft tracked a macOS ClickFix operation using over 250 front-end domains that fingerprint visitors before deciding whether to show a malware lure. The server-side gate hides malicious pages from crawlers and sandboxes while showing selected Mac users a fake download that ultimately retrieves scripts to launch infostealers such as MacSync and Atomic Stealer (AMOS). The attack still requires users to paste and run an obfuscated Terminal command, and Microsoft recommends users never paste browser instructions into Terminal.
read more →

macOS ClickFix campaign adopts server-side cloaking

🛡️ Microsoft Threat Intelligence tracked a macOS ClickFix campaign distributing infostealers such as MacSync and Atomic Stealer (AMOS) through a large family of look-alike domains. The operation shifted from embedding the malicious ClickFix lure in page HTML to hiding it behind a server-side browser-fingerprinting gate that selectively shows the lure only to visitors resembling genuine macOS browsers. The blog describes domain patterns, fingerprinting checks, infection chain, detection coverage, and hunting pivots defenders can use to find related activity.
read more →

DOUBLECUP ClickFix service hides malware in cache

🔍 SOCRadar warns of a Russian loader-as-a-service called DOUBLECUP that uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, delivering CountLoader and a new DeviceManager RAT. The service, active since June 2026, provides infrastructure and a Go-based builder while customers host phishing pages that trick users into pasting commands. The technique forces browsers to cache steganographic images, then extracts and executes payloads via clipboard-driven commands.
read more →

ESET H1 2026 report: AI skills and adaptable malware

🔍 ESET's H1 2026 Threat Report examines how attackers are scaling operations by adapting established techniques to new platforms and leveraging AI. The vendor analyzed nearly 900,000 AI skills and found tens of thousands of suspicious instances and thousands of malicious ones. AI is appearing inside malware, exemplified by Android PromptSpy using Google’s Gemini to interpret UIs and adapt behavior. The report also highlights social engineering trends like ClickFix, rising quishing, and persistent ransomware tactics such as EDR killers.
read more →

ClickFix macOS campaign and AMOS infostealer

🛡️ This post explains a macOS-focused variant of the ClickFix social-engineering attack that coerces users into pasting malicious commands into Terminal. The script downloads a hidden DMG, mounts it silently, and launches an installer that deploys the AMOS (Atomic macOS Stealer) malware. Once installed, the stealer harvests browser data, crypto wallets, desktop app credentials, Safari and Keychain data, and uploads it to attackers’ servers.
read more →

Steam forum ClickFix attacks deliver XMRig miners

🛡️ Threat actors are abusing Steam discussion forums with ClickFix social engineering posts that instruct users to run PowerShell commands purportedly to fix game or system issues. The commands download and run an XMRig cryptominer disguised as a Windows optimization utility named msf utility \ PC Opt, which fakes maintenance progress while installing a miner as C:\Windows\Background\system.exe and persisting via a scheduled task. Victims are advised to check for the Background folder, Defender exclusions, and scheduled tasks named 'XMRig-[computer name]' and to run antivirus scans or consider OS reinstall.
read more →