#clickfix

19 posts · Last used 1d

Back to Timeline
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · 2d ago
The new TAG-150 attack chain uses ClickFix to deploy DenoRAT malware and NightshadeC2. Learn how this threat targets financial sectors and crypto wallets. #TAG150 #DenoRAT #CyberSecurity #Malware #InfoSec #ClickFix https://securityonline.info/tag-150-attack-chain-denorat/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · 2d ago
Microsoft warns of rising ACR Stealer attacks using ClickFix lures to steal browser credentials and tokens from enterprises. Two chains detailed. #ACRStealer #ClickFix #Infostealer #Malware #Cybersecurity http://securityonline.info/acr-stealer-clickfix/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
ESET Research @ESETresearch@infosec.exchange · 4d ago
ESET detections of #ClickFix doubled (+108%) between H2 2025 and H1 2026 as attackers expanded beyond fake CAPTCHAs to AI platforms (#AI-fix), browser extensions (#CrashFix), and cloud authentication workflows (#ConsentFix). In AI-fix attacks, attackers craft web pages that impersonate legitimate AI services, including #Anthropic Artifacts, #OpenAI Canvas, and Microsoft #Copilot Pages. The web pages display fake troubleshooting content designed to trick users into executing malicious commands. Another ClickFix evolution, CrashFix, operates in the browser environment through a fake ad blocker, causing fake browser crashes and displaying warnings of data loss to pressure victims into following malicious "quick fix" instructions. Finally, ConsentFix targets OAuth authorization tokens instead of passwords. Victims are tricked into handing over tokens that can provide access to Microsoft accounts without the need for credential theft. Read more about the evolution of ClickFix threat landscape in the latest #ESETThreatReport: https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-threat-report-h12026.pdf
0
0
0
Cloud 🤖 @cloud@infosec.exchange · 6d ago
🤖 UAC-0145 (Sandworm/GRU) uses ClickFix fake CAPTCHAs to trick Ukrainian targets into infecting themselves with data-stealing malware. Victims paste a PowerShell script from a fake verification page. Technical breakdown by CERT-UA. 🔗 https://thehackernews.com/2026/07/uac-0145-uses-clickfix-captchas-to.html #CyberSec #Malware #Sandworm #ClickFix #APT
0
0
0
Ruchna :verified: @0x52@infosec.exchange · Jul 16, 2026
ClaudeFix: In a case of peak 2026, we've come across a campaign involving shared Claude chats hosting #ClickFix instructions to distribute a macOS infostealer. In this research for Zscaler Threat Hunting, I analyzed a malvertising campaign targeting users looking to download Claude, ironically through cleverly crafted shared Claude chats. The shared chats add a semblance of legitimacy with the label "Shared by Apple Support" (seen on the top right in the screenshot) - the TA likely achieved this by setting their display name in Claude as "Apple Support" leading to this tag when the shared chat is generated. More details on the campaign and an analysis of the delivered #MacSync stealer at https://www.zscaler.com/blogs/security-research/claudefix-shared-claude-chats-meet-clickfix
0
0
0
:awesome:🐦‍🔥nemo™🐦‍⬛ 🇺🇦🍉 @nemo@mas.to · Jul 08, 2026
🛡️ uBlock Origin’s Chrome extension has quietly added protections against ClickFix by updating its badware filter list, blocking known sites used to trick users into copying & executing malicious commands. The rules also appear to cover uBlock Origin Lite. 🔒 https://cyberinsider.com/ublock-origin-chrome-extension-now-blocks-known-clickfix-sites/ #uBlockOrigin #Cybersecurity #Malware #ClickFix
3
0
1
Between The Hacks @betweenthehacks@infosec.exchange · Jul 08, 2026
A CAPTCHA should never ask you to open Terminal. I recently encountered a real ClickFix attack while visiting a trusted website. That experience led me to investigate why attackers are increasingly impersonating security itself instead of simply impersonating trusted brands. New Between The Hacks article: https://betweenthehacks.com/blog/clickfix #ClickFix #Cybersecurity #InfoSec #SocialEngineering
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 07, 2026
uBlock Origin adds new filters to block ClickFix social engineering pop-ups and malicious commands before they reach users. #uBlockOrigin #ClickFix #MalwareProtection #SocialEngineering #BrowserSecurity https://meterpreter.org/ublock-origin-clickfix-protection/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
IFIN - The Independent Federated Intelligence Network @ifin@infosec.exchange · Jul 01, 2026
An IFIN community member caught this #ClickFix campaign, followed it, reversed the payload, and brought the IOCs. This is the juice right here. A perfect example that #ThreatIntelIsMutualAid https://discourse.ifin.network/t/compromised-website-hosting-clickfix-payload-leads-to-netsupport-rat-infection/633 #ThreatIntel #ThreatIntelligence #IFIN
22
0
17
Saltmyhash @saltmyhash@infosec.exchange · Jul 02, 2026
I was trying to carve out an encrypted blob from a PNG file last night using dd and finally triggered the new macOS ClickFix warning in my terminal. It was interesting that it fired because I wasn’t attempting to execute a commonly abused binary like osascript or make an outbound web call. While I haven’t been able to identify what XProtect is flagging on, I’m personally leaning towards either simple pattern matching for risky terms (I did have a suspicious output filename) or literally any pastes from a browser. The latter I have tried numerous times to no avail when this was first released in Tahoe 26.4, so I have no idea. FWIW, this was the offending command: dd if=clik.txt of=encrypted_payload.bin bs=1 skip=27856 status=progress https://9to5mac.com/2026/03/25/macos-26-4-has-new-terminal-popup-warning-when-pasting-commands/ #macos #malware #clickfix
0
0
0
Erik van Straten @ErikvanStraten@todon.nl · Jun 20, 2026
Replying to @ErikvanStraten@todon.nl
Waarschuwing: nep-CAPTCHA's CAPTCHA-vensters, meestal met een aantal plaatjes er in waarvan je enkele, die aan gegeven criteria voeldoen, moet aanvinken, zijn bedoeld om te voorkomen dat "bots" of "robots" webpagina's uitlezen. In https://infosec.exchange/@briankrebs/116780029181293028 meldt Brian Krebs (@briankrebs@infosec.exchange ) een nep-CAPTCHA op de Gizmodo website (zie plaatje hieronder, info in Alt text). Die nep-CAPTCHA vraagt u om onzichtbare tekst (die instructies bevat) naar het klembord te kopiëren, dat te plakken in een "terminal" of "command prompt" venster en dat uit te voeren. Daardoor wordt aanvullende kwaadaardige software gedownload en gestart. Dat dit een "ClickFix" aanval wordt genoemd hoeft u niet te onthouden, wel dat CAPTCHA's met onduidelijke instructies gevaarlijk zijn! Onderstaande is voor Windows, maar vergelijkbare CAPTCHA's zijn denkbaar voor MacOS, Linux, Android en iOS/iPadOS. TRAP ER NIET IN! Terzijde: "echte" CAPTCHA's zijn afschuwelijk: o.a. slechtziende mensen worden buitengesloten en virus/phishing scanners kunnen webpagina's niet analyseren. Bovendien vormen zij een inbreuk op uw privacy (veel CAPTCHA's komen van Google servers, waardoor Google weet dat u de pagina bezoekt) en u helpt hiermee AI te trainen. #ClickFix #Malware #Awareness #SecurityAwareness #InfoSec #BigTechIsEvil #CAPTCHA
0
0
4
Erik van Straten @ErikvanStraten@todon.nl · Jun 20, 2026
Replying to @ErikvanStraten@todon.nl
Waarschuwing: nep-CAPTCHA's - ook voor MacOS! In mijn vorige toot schreef ik dat nep-CAPTCHA's (met ClickFix aanvallen) ook denkbaar zijn voor andere besturingssystemen dan Windows. Zojuist zag ik in een toot van Kevin Beaumont (https://cyberplace.social/@GossiTheDog/116782124474589760) dat Julia Métraux (in https://bsky.app/profile/juliametraux.bsky.social/post/3moomipmam22i) eveneens op Gizmodo, een nep-CAPTCHA bestemd voor MacOS had gespot, waarvan zij een screenshot publiceerde. In die screenshot (die ik hieronder gekopieerd heb) ziet u hoe deze MacOS variant er uit zag. Nogmaals, TRAP HIER NIET IN! #ClickFix #Malware #Awareness #SecurityAwareness #InfoSec #BigTechIsEvil #CAPTCHA
1
0
3
BrianKrebs @briankrebs@infosec.exchange · Jun 20, 2026
Boosted by Trending Bot @trending@homestead.social
Don't look now, but it seems Gizmodo's homepage is now serving up a Clickfix attack. Basics of the Click-Fix exploit, which causes a pasted URL to fetch malware via Windows Powershell. https://krebsonsecurity.com/2025/03/clickfix-how-to-infect-your-pc-in-three-easy-steps/ #clickfix #gizmodo
18
1
27
Italian News by RSS @ItalianNews@mastodon.ozioso.online · Mar 30, 2026
Punto Informatico: Infiniti Stealer: nuovo malware per macOS con ClickFix Infiniti Stealer è un nuovo malware per macOS che viene distribuito con la tecnica ClickFix e permette di rubare molti dati sensibili dal dispositivo. The post Infiniti Stealer: nuovo malware per macOS con ClickFix appeared first on Punto Informatico. Infiniti Stealer: New macOS Malware Using ClickFix Infiniti Stealer is a new malware for macOS that is distributed using the ClickFix technique and allows the theft of many sensitive data from the device. The post Infiniti Stealer: new malware for macOS with ClickFix appeared first on Punto Informatico. #Infiniti #NewmacOSMalware #ClickFix #first #PuntoInformatico https://www.punto-informatico.it/infiniti-stealer-nuovo-malware-per-macos-clickfix/
0
0
0

You've seen all posts