Brevo delivered ClickFix malware to 51 of its own customers
Kirk at ADAMnetworks found Brevo serving ClickFix malware from its own infrastructure to 51 customer sites. I took part in the investigation using whack.sh.
https://tuxxin.com/blog/brevo-clickfix-customer-sites
#security #threatintelligence #whacksh #clickfix
About This Hashtag
#clickfix
25 posts
Last used 3d
#clickfix
25 posts· Last used 3d
A new TerminalFix campaign uses fake CAPTCHAs to breach systems. Explore the TerminalFix attack chain and its covert reverse tunnel.
#TerminalFix #ClickFix #Malware #Cybersecurity #ThreatIntel
https://securityonline.info/terminalfix-campaign-reverse-tunnel/?utm_source=mastodon&utm_medium=jetpack_social
StopAndProtect malware turns hacked WordPress sites into a botnet for ransomware and data theft. Check Point exposed 5,000+ victims.
#StopAndProtect #WordPressSecurity #Ransomware #ClickFix #CyberSecurity
http://securityonline.info/stopandprotect-malware-hacked-wordpress-sites/?utm_source=mastodon&utm_medium=jetpack_social
"ClickFix, EtherHiding & a DPRK Wallet Trail" published by Allsecure. #ContagiousInterview, #ClickFix, #UNC5342, #EtherHiding https://www.allsecure.io/blog/clickfix-etherhiding-dprk-wallet
JUMPSEC analyzed the BlueNoroff phishing kit's source code. The DPRK ClickFix attack fakes Zoom and Teams calls to profile and drain crypto wallets.
#BlueNoroff #ClickFix #Lazarus #CryptoTheft
https://securityonline.info/bluenoroff-phishing-kit/?utm_source=mastodon&utm_medium=jetpack_social
BlueNoroff ClickFix Phishing Targets Crypto via Zoom
🔗 https://cybersecurefox.com/en/bluenoroff-clickfix-zoom-teams-crypto-phishing
#BlueNoroff #ClickFix #phishing #Zoom #Microsoft #Teams
"Inside a DPRK BlueNoroff ClickFix Kit" published by Jumpsec. #Phishing, #Bluenoroff, #NukeSped, #Cloudzy, #Telegram, #ClickFix https://www.jumpsec.com/guides/inside-a-dprk-bluenoroff-clickfix-kit
The new TAG-150 attack chain uses ClickFix to deploy DenoRAT malware and NightshadeC2. Learn how this threat targets financial sectors and crypto wallets.
#TAG150 #DenoRAT #CyberSecurity #Malware #InfoSec #ClickFix
https://securityonline.info/tag-150-attack-chain-denorat/?utm_source=mastodon&utm_medium=jetpack_social
Microsoft warns of rising ACR Stealer attacks using ClickFix lures to steal browser credentials and tokens from enterprises. Two chains detailed.
#ACRStealer #ClickFix #Infostealer #Malware #Cybersecurity
http://securityonline.info/acr-stealer-clickfix/?utm_source=mastodon&utm_medium=jetpack_social
ESET detections of #ClickFix doubled (+108%) between H2 2025 and H1 2026 as attackers expanded beyond fake CAPTCHAs to AI platforms (#AI-fix), browser extensions (#CrashFix), and cloud authentication workflows (#ConsentFix).
In AI-fix attacks, attackers craft web pages that impersonate legitimate AI services, including #Anthropic Artifacts, #OpenAI Canvas, and Microsoft #Copilot Pages. The web pages display fake troubleshooting content designed to trick users into executing malicious commands.
Another ClickFix evolution, CrashFix, operates in the browser environment through a fake ad blocker, causing fake browser crashes and displaying warnings of data loss to pressure victims into following malicious "quick fix" instructions.
Finally, ConsentFix targets OAuth authorization tokens instead of passwords. Victims are tricked into handing over tokens that can provide access to Microsoft accounts without the need for credential theft. Read more about the evolution of ClickFix threat landscape in the latest #ESETThreatReport: https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-threat-report-h12026.pdf
"DPRK’s Famous Chollima Deploys RATs Through ClickFake Job Interviews" published by SOCRadar. #FamousChollima, #ClickFix, #GolangGhost, #PylangGhost https://socradar.io/blog/dprk-clickfake-pylangghost-golangghost-rats/
#clickfix to #vidar (among other things) via:
http:// www\.apcconstruction\.com/
https://app.any.run/tasks/4599dbb0-1041-43f3-b127-a42cfc7ca60e
ClickLock Stealer: New macOS Malware Hijacks Desktop
🔗 https://cybersecurefox.com/en/clicklock-stealer-macos-infostealer
#clicklock #stealer #macos #malware #macos #infostealer #group-ib #clickfix
🤖 UAC-0145 (Sandworm/GRU) uses ClickFix fake CAPTCHAs to trick Ukrainian targets into infecting themselves with data-stealing malware. Victims paste a PowerShell script from a fake verification page. Technical breakdown by CERT-UA.
🔗 https://thehackernews.com/2026/07/uac-0145-uses-clickfix-captchas-to.html
#CyberSec #Malware #Sandworm #ClickFix #APT
ClaudeFix: In a case of peak 2026, we've come across a campaign involving shared Claude chats hosting #ClickFix instructions to distribute a macOS infostealer.
In this research for Zscaler Threat Hunting, I analyzed a malvertising campaign targeting users looking to download Claude, ironically through cleverly crafted shared Claude chats. The shared chats add a semblance of legitimacy with the label "Shared by Apple Support" (seen on the top right in the screenshot) - the TA likely achieved this by setting their display name in Claude as "Apple Support" leading to this tag when the shared chat is generated.
More details on the campaign and an analysis of the delivered #MacSync stealer at https://www.zscaler.com/blogs/security-research/claudefix-shared-claude-chats-meet-clickfix
🛡️ uBlock Origin’s Chrome extension has quietly added protections against ClickFix by updating its badware filter list, blocking known sites used to trick users into copying & executing malicious commands. The rules also appear to cover uBlock Origin Lite. 🔒
https://cyberinsider.com/ublock-origin-chrome-extension-now-blocks-known-clickfix-sites/ #uBlockOrigin #Cybersecurity #Malware #ClickFix
A CAPTCHA should never ask you to open Terminal.
I recently encountered a real ClickFix attack while visiting a trusted website. That experience led me to investigate why attackers are increasingly impersonating security itself instead of simply impersonating trusted brands.
New Between The Hacks article:
https://betweenthehacks.com/blog/clickfix
#ClickFix #Cybersecurity #InfoSec #SocialEngineering
uBlock Origin adds new filters to block ClickFix social engineering pop-ups and malicious commands before they reach users.
#uBlockOrigin #ClickFix #MalwareProtection #SocialEngineering #BrowserSecurity
https://meterpreter.org/ublock-origin-clickfix-protection/?utm_source=mastodon&utm_medium=jetpack_social
An IFIN community member caught this #ClickFix campaign, followed it, reversed the payload, and brought the IOCs. This is the juice right here. A perfect example that #ThreatIntelIsMutualAid
https://discourse.ifin.network/t/compromised-website-hosting-clickfix-payload-leads-to-netsupport-rat-infection/633
#ThreatIntel #ThreatIntelligence #IFIN