#clickfix — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #clickfix, aggregated by home.social.
-
2026-08-12 (Wednesday): #SmartApeSG #ClickFix leads to two RATs. A #pcap of the traffic, malware, artifacts and more info available at https://www.malware-traffic-analysis.net/2026/08/12/index.html
-
2026-08-12 (Wednesday): #SmartApeSG #ClickFix leads to two RATs. A #pcap of the traffic, malware, artifacts and more info available at https://www.malware-traffic-analysis.net/2026/08/12/index.html
-
🚨 Over 500 compromised WordPress sites have been caught serving fake Cloudflare verification prompts as part of a #ClickFix campaign targeting Windows users for browser data, crypto wallet information, and keystrokes.
Listen/Read: https://hackread.com/wordpress-sites-hacked-infostealer-clickfix-attack/
-
🚨 Over 500 compromised WordPress sites have been caught serving fake Cloudflare verification prompts as part of a #ClickFix campaign targeting Windows users for browser data, crypto wallet information, and keystrokes.
Listen/Read: https://hackread.com/wordpress-sites-hacked-infostealer-clickfix-attack/
-
New.
Sophos: ClickFix campaign abuses Deno runtime for infostealer delivery https://www.sophos.com/en-us/blog/clickfix-campaign-abuses-deno-runtime-for-infostealer-delivery @SophosXOps #infosec #cyberattack #threatresearch #ClickFix
-
New.
Sophos: ClickFix campaign abuses Deno runtime for infostealer delivery https://www.sophos.com/en-us/blog/clickfix-campaign-abuses-deno-runtime-for-infostealer-delivery @SophosXOps #infosec #cyberattack #threatresearch #ClickFix
-
macOS Malware Uses ClickFix to Steal Crypto, Passwords and Keychain Secrets - https://www.redpacketsecurity.com/go-based-macos-malware-steals-crypto-and-secrets/
-
macOS Malware Uses ClickFix to Steal Crypto, Passwords and Keychain Secrets - https://www.redpacketsecurity.com/go-based-macos-malware-steals-crypto-and-secrets/
-
-
-
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide - https://www.redpacketsecurity.com/from-open-lures-to-cloaked-gates-how-a-macos-clickfix-campaign-learned-to-hide/
#threatintel
#ClickFix
#macOS Malware
#Atomic Stealer (AMOS)
#Browser Fingerprinting
#Information Stealers -
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide - https://www.redpacketsecurity.com/from-open-lures-to-cloaked-gates-how-a-macos-clickfix-campaign-learned-to-hide/
#threatintel
#ClickFix
#macOS Malware
#Atomic Stealer (AMOS)
#Browser Fingerprinting
#Information Stealers -
⚠️ PSA: This is a scam, not a real Cloudflare check.
If a "Human Verification" popup tells you to press Win+R (or open Terminal), paste something, and hit Enter — close the tab immediately. Real bot checks never ask you to run commands on your computer 🚫💻
-
⚠️ PSA: This is a scam, not a real Cloudflare check.
If a "Human Verification" popup tells you to press Win+R (or open Terminal), paste something, and hit Enter — close the tab immediately. Real bot checks never ask you to run commands on your computer 🚫💻
-
Kerala Police has warned the public about the 'ClickFix' cyber scam, where fake CAPTCHA prompts trick users into installing malware that steals banking details, passwords and email accounts. https://english.mathrubhumi.com/news/kerala/dont-click-that-captcha-kerala-police-warns-of-clickfix-cyber-scam-hf2c8v99?utm_source=dlvr.it&utm_medium=mastodon #ClickFix #CyberScam #KeralaPolice #CyberSecurity #FakeCAPTCHA
-
2026-07-31 (Friday): #SmartApeSG #ClickFix campaign pushes unidentified #RAT malware. A #pcap of the infection traffic, the associated malware files, and further info available at https://www.malware-traffic-analysis.net/2026/07/31/index.html
-
2026-07-31 (Friday): #SmartApeSG #ClickFix campaign pushes unidentified #RAT malware. A #pcap of the infection traffic, the associated malware files, and further info available at https://www.malware-traffic-analysis.net/2026/07/31/index.html
-
Anscheinend sind Fake Captchas gerade das neue große Ding, bei denen keine Feuerwehrautos angeklickt werden müssen, sondern Tastenkombinationen auf der Tastatur, mit denen dann Malware installiert wird.
Gestern sollte ich mit dem Handy einen QR Code vom Bildschirm scannen. (As if)
#clickfix -
Neuer #ClickFix-Angriff auf Mac-Nutzer im Umlauf: Erpressung trifft auf Datenklau | Mac & i https://www.heise.de/news/Neuer-ClickFix-Angriff-auf-Mac-Nutzer-im-Umlauf-Erpressung-trifft-auf-Datenklau-11373483.html #macOS #Apple :apple_inc: #ClickLockStealer
-
Neuer #ClickFix-Angriff auf Mac-Nutzer im Umlauf: Erpressung trifft auf Datenklau | Mac & i https://www.heise.de/news/Neuer-ClickFix-Angriff-auf-Mac-Nutzer-im-Umlauf-Erpressung-trifft-auf-Datenklau-11373483.html #macOS #Apple :apple_inc: #ClickLockStealer
-
ACR Stealer: Two observed intrusion chains amid increased threat activity - https://www.redpacketsecurity.com/acr-stealer-two-observed-intrusion-chains-amid-increased-threat-activity/
#threatintel
#ACR Stealer
#ClickFix
#WebDAV
#PowerShell
#Credential theft -
ACR Stealer: Two observed intrusion chains amid increased threat activity - https://www.redpacketsecurity.com/acr-stealer-two-observed-intrusion-chains-amid-increased-threat-activity/
#threatintel
#ACR Stealer
#ClickFix
#WebDAV
#PowerShell
#Credential theft -
ClickFake Campaign: North Korean-Linked Social Engineering Targets Web3 Professionals - https://www.redpacketsecurity.com/researchers-uncover-north-korean-clickfake-campaign-targeting-web3-pros/
-
ClickFake Campaign: North Korean-Linked Social Engineering Targets Web3 Professionals - https://www.redpacketsecurity.com/researchers-uncover-north-korean-clickfake-campaign-targeting-web3-pros/
-
https://winbuzzer.com/2026/07/21/microsoft-warns-of-increased-acr-stealer-activity-xcxwbn/
Microsoft warns that increased ACR Stealer activity uses ClickFix, WebDAV, and MSHTA routes to steal enterprise credentials, tokens, and cloud documents.
#AcrStealer #ClickFix #Microsoft #Malware #CyberThreats #Cyberattacks #MicrosoftDefender #MicrosoftSecurity #Microsoft365
-
https://winbuzzer.com/2026/07/21/microsoft-warns-of-increased-acr-stealer-activity-xcxwbn/
Microsoft warns that increased ACR Stealer activity uses ClickFix, WebDAV, and MSHTA routes to steal enterprise credentials, tokens, and cloud documents.
#AcrStealer #ClickFix #Microsoft #Malware #CyberThreats #Cyberattacks #MicrosoftDefender #MicrosoftSecurity #Microsoft365
-
#clickfix to #vidar (among other things) via:
http:// www\.apcconstruction\.com/
https://app.any.run/tasks/4599dbb0-1041-43f3-b127-a42cfc7ca60e
-
#clickfix to #vidar (among other things) via:
http:// www\.apcconstruction\.com/
https://app.any.run/tasks/4599dbb0-1041-43f3-b127-a42cfc7ca60e
-
Ein kopierter Befehl, dein ganzes Microsoft-Konto: die ACR-Stealer-Welle erklärt
Ein gefälschtes Captcha, ein Klick, ein eingefügter Befehl in die PowerShell: ACR Stealer holt sich dein Microsoft-Konto und mit ihm jedes Dokument aus OneDrive und SharePoint. Microsoft warnt seit dem 16. Juli 2026 in aller Deutlichkeit, wie gut das funktioniert.
#chrislo #ITSicherheit #DigitaleUnabhängigkeit #ACRStealer #ClickFix #Malware #Microsoft #OneDrive #SharePoint #ZweiFaktorAuthentifizierung #Backup #Windows
-
Ein kopierter Befehl, dein ganzes Microsoft-Konto: die ACR-Stealer-Welle erklärt
Ein gefälschtes Captcha, ein Klick, ein eingefügter Befehl in die PowerShell: ACR Stealer holt sich dein Microsoft-Konto und mit ihm jedes Dokument aus OneDrive und SharePoint. Microsoft warnt seit dem 16. Juli 2026 in aller Deutlichkeit, wie gut das funktioniert.
#chrislo #ITSicherheit #DigitaleUnabhängigkeit #ACRStealer #ClickFix #Malware #Microsoft #OneDrive #SharePoint #ZweiFaktorAuthentifizierung #Backup #Windows
-
OkoBot: il framework che si inietta in Ledger Live e Trezor Suite per rubare le seed phrase
Kaspersky documenta OkoBot, un framework modulare con oltre venti impianti attivo da aprile 2025: si inietta nei processi Electron di Ledger Live e Trezor Suite mostrando pagine di phishing hard-coded per rubare le seed phrase dei wallet hardware. -
OkoBot: il framework che si inietta in Ledger Live e Trezor Suite per rubare le seed phrase
Kaspersky documenta OkoBot, un framework modulare con oltre venti impianti attivo da aprile 2025: si inietta nei processi Electron di Ledger Live e Trezor Suite mostrando pagine di phishing hard-coded per rubare le seed phrase dei wallet hardware. -
📣🚨 A new and active #OkoBot malware campaign is abusing the ClickFix tactic and fake GitHub repos to trick users into installing fake browser extensions that steal personal and crypto wallet data.
Listen to or read this news: https://hackread.com/okobot-malware-clickfix-browser-extensions-crypto-data/
-
📣🚨 A new and active #OkoBot malware campaign is abusing the ClickFix tactic and fake GitHub repos to trick users into installing fake browser extensions that steal personal and crypto wallet data.
Listen to or read this news: https://hackread.com/okobot-malware-clickfix-browser-extensions-crypto-data/
-
Fresh clickfix domain at linenregistry[.]top you should hunt and block
-
🛡️ uBlock Origin’s Chrome extension has quietly added protections against ClickFix by updating its badware filter list, blocking known sites used to trick users into copying & executing malicious commands. The rules also appear to cover uBlock Origin Lite. 🔒
https://cyberinsider.com/ublock-origin-chrome-extension-now-blocks-known-clickfix-sites/ #uBlockOrigin #Cybersecurity #Malware #ClickFix
Appearently misleading check out the replies.
-
RE: https://infosec.exchange/@betweenthehacks/116885082512333574
I recently encountered a ClickFix attack while visiting a trusted website. After reproducing it across multiple browsers, I realized the larger story isn’t just the malware, it’s how attackers are increasingly impersonating security mechanisms themselves.
I wrote about the experience and what it means for users and organizations.
-
A CAPTCHA should never ask you to open Terminal.
I recently encountered a real ClickFix attack while visiting a trusted website. That experience led me to investigate why attackers are increasingly impersonating security itself instead of simply impersonating trusted brands.
New Between The Hacks article:
-
🔎 Opera adds native protection against ClickFix scams
#Opera now detects and blocks #ClickFix style social engineering pages before users can execute the malicious commands they display.
🔗 read more: lifehacker.com/tech/opera-r...
#ransomNews #cybersecurity -
📣🚨 Fake Google and Cloudflare verification pages are being abused in new ClickFix campaigns that deliver seven malware families, including some of the most notorious infostealers seen in recent months.
Listen or Read: https://hackread.com/clickfix-scam-google-cloudflare-7-malware-families/