< ciso
brief />
Tag Banner

All news with #clickfix tag

95 articles

AmnesiaStealer macOS malware hijacks browser sessions

🛡️ A new macOS infostealer called AmnesiaStealer uses ClickFix campaigns to deliver a Mach-O payload inside a password-protected archive. It copies Chromium profiles and launches hidden, headless browser instances to preserve authentication state while enabling remote operator control. The malware exfiltrates passwords, keychain items, crypto wallets, browser data across 16 Chromium-based browsers, and streams live screencasts and input via WebSocket channels. Researchers at Jamf warn the module abuses the Chrome DevTools Protocol to let attackers navigate and act in victims' authenticated sessions.
read more →

New macOS infostealer spreads via ClickFix lure

🛡️ Researchers at Jamf warn of a Rust-based macOS infostealer named AmnesiaStealer distributed through ClickFix social engineering. The malware harvests credentials, browser data and live sessions, uses OS version–specific bypasses, and includes a remote-controlled second stage to stealthily control Chromium-family browsers. Jamf recommends enabling threat prevention, advanced threat controls and web protection set to Block and Report.
read more →

ClickFix macOS infostealer targets crypto and credentials

🛡️ A Go-based malware delivered via a ClickFix campaign targets macOS users to steal cryptocurrency, browser passwords, Apple Keychain data, and cached credentials. Researchers at Huntress found the attack uses a Bash profiler and Mach-O payload tailored to the victim’s CPU, persists by faking errors with osascript, and removes quarantine flags to bypass Gatekeeper. The malware can intercept and divert crypto transactions and selectively drain a percentage of funds.
read more →

macOS ClickFix campaign uses browser fingerprinting

🛡️ Microsoft tracked a macOS ClickFix operation using over 250 front-end domains that fingerprint visitors before deciding whether to show a malware lure. The server-side gate hides malicious pages from crawlers and sandboxes while showing selected Mac users a fake download that ultimately retrieves scripts to launch infostealers such as MacSync and Atomic Stealer (AMOS). The attack still requires users to paste and run an obfuscated Terminal command, and Microsoft recommends users never paste browser instructions into Terminal.
read more →

macOS ClickFix campaign adopts server-side cloaking

🛡️ Microsoft Threat Intelligence tracked a macOS ClickFix campaign distributing infostealers such as MacSync and Atomic Stealer (AMOS) through a large family of look-alike domains. The operation shifted from embedding the malicious ClickFix lure in page HTML to hiding it behind a server-side browser-fingerprinting gate that selectively shows the lure only to visitors resembling genuine macOS browsers. The blog describes domain patterns, fingerprinting checks, infection chain, detection coverage, and hunting pivots defenders can use to find related activity.
read more →

DOUBLECUP ClickFix service hides malware in cache

🔍 SOCRadar warns of a Russian loader-as-a-service called DOUBLECUP that uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, delivering CountLoader and a new DeviceManager RAT. The service, active since June 2026, provides infrastructure and a Go-based builder while customers host phishing pages that trick users into pasting commands. The technique forces browsers to cache steganographic images, then extracts and executes payloads via clipboard-driven commands.
read more →

ESET H1 2026 report: AI skills and adaptable malware

🔍 ESET's H1 2026 Threat Report examines how attackers are scaling operations by adapting established techniques to new platforms and leveraging AI. The vendor analyzed nearly 900,000 AI skills and found tens of thousands of suspicious instances and thousands of malicious ones. AI is appearing inside malware, exemplified by Android PromptSpy using Google’s Gemini to interpret UIs and adapt behavior. The report also highlights social engineering trends like ClickFix, rising quishing, and persistent ransomware tactics such as EDR killers.
read more →

ClickFix macOS campaign and AMOS infostealer

🛡️ This post explains a macOS-focused variant of the ClickFix social-engineering attack that coerces users into pasting malicious commands into Terminal. The script downloads a hidden DMG, mounts it silently, and launches an installer that deploys the AMOS (Atomic macOS Stealer) malware. Once installed, the stealer harvests browser data, crypto wallets, desktop app credentials, Safari and Keychain data, and uploads it to attackers’ servers.
read more →

Steam forum ClickFix attacks deliver XMRig miners

🛡️ Threat actors are abusing Steam discussion forums with ClickFix social engineering posts that instruct users to run PowerShell commands purportedly to fix game or system issues. The commands download and run an XMRig cryptominer disguised as a Windows optimization utility named msf utility \ PC Opt, which fakes maintenance progress while installing a miner as C:\Windows\Background\system.exe and persisting via a scheduled task. Victims are advised to check for the Background folder, Defender exclusions, and scheduled tasks named 'XMRig-[computer name]' and to run antivirus scans or consider OS reinstall.
read more →

ConsentFix: OAuth-based Microsoft 365 account hijacking

🛡️Researchers uncovered a new ClickFix variant called ConsentFix that tricks users into granting OAuth tokens, enabling attackers to access Microsoft 365 accounts without stealing passwords. Attackers use deceptive pages and social engineering—often via phishing emails imitating file-sharing services—to induce victims to drag a tokenized URL onto an attacker-controlled page. Once obtained, the OAuth token can expose Outlook, Teams, OneDrive, SharePoint and other services depending on the organization’s license and privileges, enabling data exfiltration, BEC and lateral movement. The technique is widely shared on cybercrime forums with tutorials and turnkey tools, increasing its prevalence and lowering the barrier for novice threat actors.
read more →

Fake CAPTCHA Click-Fraud Used to Activate Malware

🔒 Ukraine's CERT-UA warns that Russian-linked Sandworm actors are using fake CAPTCHA prompts on compromised sites to trick users into pasting and executing PowerShell commands on their PCs. The campaign, attributed to UAC-0145, began surging in June and has compromised at least ten websites, deploying a reconnaissance tool called ScoutCurl. These "ClickFix" attacks coerce victims to run legitimate tools like PowerShell, making them effective and dangerous.
read more →

Microsoft warns of surge in ACR Stealer attacks

🛡️ Microsoft reports a marked increase in attacks leveraging ACR Stealer, an info-stealing MaaS that exfiltrates browser passwords, tokens, and sensitive documents from enterprise environments. Between late April and mid‑June, threat actors used social engineering (ClickFix), WebDAV servers, and mshta.exe to deliver obfuscated PowerShell loaders, Python-based installers, and in-memory payloads. The actor abuses GUID-based WebDAV paths, steganographic JPEGs, and public blockchains as dead-drop resolvers to mask activity and maintain C2 communications. Microsoft recommends filters, application control, and limiting access to unnecessary web resources to reduce exposure.
read more →

ACR Stealer campaigns use ClickFix lures and fileless tradecraft

🔍 Microsoft Defender Experts observed heightened ACR Stealer activity from late April to mid-June 2026, using ClickFix social engineering to lure users into running commands that ultimately harvest browser credentials, tokens, and sensitive documents. Two prevalent campaigns were detailed: one using WebDAV-delivered DLLs, staged PowerShell, Python loaders, and optional blockchain-backed dead-drop C2 resolution; the other using fileless MSHTA, obfuscated PowerShell, and steganography-assisted in-memory execution. Both aim to exfiltrate credentials and enterprise data, and Microsoft recommends monitoring for ClickFix lures, suspicious WebDAV/MSHTA activity, obfuscated PowerShell, and attempts to access browser credential stores while leveraging Defender capabilities to detect and respond.
read more →

OkoBot framework deploys 20+ payloads to steal crypto

🛡️ A new modular malware framework named OkoBot delivers over 20 payloads to steal cryptocurrency seed phrases, credentials, and other sensitive data. The campaign uses ClickFix lures and malicious GitHub repositories, sometimes trojanizing legitimate tools, and evolved from the earlier TookPS activity. Kaspersky found the campaign active since January and primarily targeting victims in Brazil, Vietnam, Canada, Mexico, and Turkey. Notable modules include browser injectors, SeedHunter for wallet recovery prompts, keyloggers, and spyware that records wallet and password manager windows.
read more →

ClickLock macOS stealer leverages ClickFix social lure

🛡️ Group-IB researchers describe a new macOS stealer called ClickLock that combines a ClickFix "paste-a-command" lure with a coercion routine that disables the desktop until a password is surrendered. The modular campaign downloaded four components from compromised WordPress sites to steal Keychain and browser credentials, exfiltrate wallet data, and install a GSocket backdoor. Operators forced compliance by killing system processes in loops, suppressing warnings and relaunching credential prompts; exfiltration used Telegram bots and modules self-deleted, leaving a stealthy backdoor.
read more →

TELEPUZ modular malware spreads via ClickFix attacks

🛡️ Elastic Security Labs disclosed a new lightweight, modular malware named TELEPUZ that has been propagated through ClickFix (pastejacking) lures since late April 2026. The campaign delivers a Go-based Vidar stealer variant which then fetches a C-based TELEPUZ stager and main DLL, with artifacts hosted on a domain linked to the campaign. TELEPUZ includes extensive obfuscation, anti-VM and geofencing checks, AMSI/ETW unhooking, privilege escalation, service persistence, and WebSocket-based C2 with fallback retrieval via Telegram, Steam, DNS and a Polygon smart contract.
read more →

ConsentFix and ClickFix: Microsoft 365 hijacks

🔒 Modern phishing variants like ClickFix and the newer ConsentFix convert routine user actions into account takeover opportunities. Attackers trick victims into executing keyboard shortcuts or dragging callback links, which hands over OAuth tokens and session access to Microsoft 365 services without passwords or MFA bypass. The technique relies on familiar workflows and readily available tooling, with public sharing of blueprints lowering the barrier to entry.
read more →

Opera adds Paste Protect to block ClickFix attacks

🛡️ Opera has added Paste Protect, a feature that intercepts and blocks ClickFix-style attacks which trick users into copying and running malicious commands. The mechanism builds on existing Hijack protection and a new Injection protection to detect and prevent harmful content from reaching the browser clipboard across Windows, macOS, and Linux. When suspicious content is blocked, Opera shows a warning, a red indicator in the address bar, and permits viewing the first 120 characters or approving the copy after a 5-second delay. The feature is enabled by default and can be managed via Settings → Privacy & Security → Paste Protect.
read more →

ClickFix Emerges as Dominant Malware Delivery Method

🔒 Analysis by ReliaQuest shows the ClickFix social engineering technique dominated malware delivery from March to May 2026. ClickFix tricks users into pasting attacker-supplied commands into trusted dialogs like Run, Terminal, or Script Editor, allowing payloads such as infostealers to execute while evading many defenses. The method has been used to deliver Windows malware and, notably, to deploy AMOS/Atomic Stealer to macOS via Script Editor. ReliaQuest urges equal monitoring for macOS and recommends user training and administrative restrictions to mitigate ClickFix risks.
read more →

ClickFix: New social engineering that forces execution

🛡️ The ClickFix technique tricks users into executing malicious commands themselves by presenting convincing prompts like fake CAPTCHAs, Cloudflare checks, or “browser update” notices. Attackers rely on clipboard copy and instruct victims to paste commands into the Windows Run dialog, bypassing endpoint defenses that see the activity as legitimate user action. Check Point’s ThreatCloud AI team developed the ClickFix Engine, integrated into Gateways, Email Security, and Browse Security, to detect behavioral signals in page HTML and block such attacks irrespective of domain reputation.
read more →