#clickfix

25 posts· Last used 3d

ESET detections of #ClickFix doubled (+108%) between H2 2025 and H1 2026 as attackers expanded beyond fake CAPTCHAs to AI platforms (#AI-fix), browser extensions (#CrashFix), and cloud authentication workflows (#ConsentFix). In AI-fix attacks, attackers craft web pages that impersonate legitimate AI services, including #Anthropic Artifacts, #OpenAI Canvas, and Microsoft #Copilot Pages. The web pages display fake troubleshooting content designed to trick users into executing malicious commands. Another ClickFix evolution, CrashFix, operates in the browser environment through a fake ad blocker, causing fake browser crashes and displaying warnings of data loss to pressure victims into following malicious "quick fix" instructions. Finally, ConsentFix targets OAuth authorization tokens instead of passwords. Victims are tricked into handing over tokens that can provide access to Microsoft accounts without the need for credential theft. Read more about the evolution of ClickFix threat landscape in the latest #ESETThreatReport: https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-threat-report-h12026.pdf
2
0
2
0
ClaudeFix: In a case of peak 2026, we've come across a campaign involving shared Claude chats hosting #ClickFix instructions to distribute a macOS infostealer. In this research for Zscaler Threat Hunting, I analyzed a malvertising campaign targeting users looking to download Claude, ironically through cleverly crafted shared Claude chats. The shared chats add a semblance of legitimacy with the label "Shared by Apple Support" (seen on the top right in the screenshot) - the TA likely achieved this by setting their display name in Claude as "Apple Support" leading to this tag when the shared chat is generated. More details on the campaign and an analysis of the delivered #MacSync stealer at https://www.zscaler.com/blogs/security-research/claudefix-shared-claude-chats-meet-clickfix
0
0
0
0
🛡️ uBlock Origin’s Chrome extension has quietly added protections against ClickFix by updating its badware filter list, blocking known sites used to trick users into copying & executing malicious commands. The rules also appear to cover uBlock Origin Lite. 🔒 https://cyberinsider.com/ublock-origin-chrome-extension-now-blocks-known-clickfix-sites/ #uBlockOrigin #Cybersecurity #Malware #ClickFix
13
2
10
0