home.social

#clickfix — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #clickfix, aggregated by home.social.

fetched live
  1. 2026-08-12 (Wednesday): #SmartApeSG #ClickFix leads to two RATs. A #pcap of the traffic, malware, artifacts and more info available at malware-traffic-analysis.net/2

  2. 2026-08-12 (Wednesday): #SmartApeSG #ClickFix leads to two RATs. A #pcap of the traffic, malware, artifacts and more info available at malware-traffic-analysis.net/2

  3. 🚨 Over 500 compromised WordPress sites have been caught serving fake Cloudflare verification prompts as part of a #ClickFix campaign targeting Windows users for browser data, crypto wallet information, and keystrokes.

    Listen/Read: hackread.com/wordpress-sites-h

    #CyberSecurity #WordPress #Malware #Cloudflare #Infostealer

  4. 🚨 Over 500 compromised WordPress sites have been caught serving fake Cloudflare verification prompts as part of a #ClickFix campaign targeting Windows users for browser data, crypto wallet information, and keystrokes.

    Listen/Read: hackread.com/wordpress-sites-h

    #CyberSecurity #WordPress #Malware #Cloudflare #Infostealer

  5. ⚠️ PSA: This is a scam, not a real Cloudflare check.

    If a "Human Verification" popup tells you to press Win+R (or open Terminal), paste something, and hit Enter — close the tab immediately. Real bot checks never ask you to run commands on your computer 🚫💻

    #CyberSecurity #ScamAlert #ClickFix

  6. ⚠️ PSA: This is a scam, not a real Cloudflare check.

    If a "Human Verification" popup tells you to press Win+R (or open Terminal), paste something, and hit Enter — close the tab immediately. Real bot checks never ask you to run commands on your computer 🚫💻

    #CyberSecurity #ScamAlert #ClickFix

  7. 2026-07-31 (Friday): #SmartApeSG #ClickFix campaign pushes unidentified #RAT malware. A #pcap of the infection traffic, the associated malware files, and further info available at malware-traffic-analysis.net/2

  8. 2026-07-31 (Friday): #SmartApeSG #ClickFix campaign pushes unidentified #RAT malware. A #pcap of the infection traffic, the associated malware files, and further info available at malware-traffic-analysis.net/2

  9. Anscheinend sind Fake Captchas gerade das neue große Ding, bei denen keine Feuerwehrautos angeklickt werden müssen, sondern Tastenkombinationen auf der Tastatur, mit denen dann Malware installiert wird.
    Gestern sollte ich mit dem Handy einen QR Code vom Bildschirm scannen. (As if)
    #clickfix

  10. Ein kopierter Befehl, dein ganzes Microsoft-Konto: die ACR-Stealer-Welle erklärt

    Ein gefälschtes Captcha, ein Klick, ein eingefügter Befehl in die PowerShell: ACR Stealer holt sich dein Microsoft-Konto und mit ihm jedes Dokument aus OneDrive und SharePoint. Microsoft warnt seit dem 16. Juli 2026 in aller Deutlichkeit, wie gut das funktioniert.

    chrislo.de/blog/2026-07-19-19-

    #chrislo #ITSicherheit #DigitaleUnabhängigkeit #ACRStealer #ClickFix #Malware #Microsoft #OneDrive #SharePoint #ZweiFaktorAuthentifizierung #Backup #Windows

  11. Ein kopierter Befehl, dein ganzes Microsoft-Konto: die ACR-Stealer-Welle erklärt

    Ein gefälschtes Captcha, ein Klick, ein eingefügter Befehl in die PowerShell: ACR Stealer holt sich dein Microsoft-Konto und mit ihm jedes Dokument aus OneDrive und SharePoint. Microsoft warnt seit dem 16. Juli 2026 in aller Deutlichkeit, wie gut das funktioniert.

    chrislo.de/blog/2026-07-19-19-

    #chrislo #ITSicherheit #DigitaleUnabhängigkeit #ACRStealer #ClickFix #Malware #Microsoft #OneDrive #SharePoint #ZweiFaktorAuthentifizierung #Backup #Windows

  12. OkoBot: il framework che si inietta in Ledger Live e Trezor Suite per rubare le seed phrase

    Kaspersky documenta OkoBot, un framework modulare con oltre venti impianti attivo da aprile 2025: si inietta nei processi Electron di Ledger Live e Trezor Suite mostrando pagine di phishing hard-coded per rubare le seed phrase dei wallet hardware.

    insicurezzadigitale.com/okobot

  13. OkoBot: il framework che si inietta in Ledger Live e Trezor Suite per rubare le seed phrase

    Kaspersky documenta OkoBot, un framework modulare con oltre venti impianti attivo da aprile 2025: si inietta nei processi Electron di Ledger Live e Trezor Suite mostrando pagine di phishing hard-coded per rubare le seed phrase dei wallet hardware.

    insicurezzadigitale.com/okobot

  14. 📣🚨 A new and active #OkoBot malware campaign is abusing the ClickFix tactic and fake GitHub repos to trick users into installing fake browser extensions that steal personal and crypto wallet data.

    Listen to or read this news: hackread.com/okobot-malware-cl

    #CyberSecurity #Malware #ClickFix #Crypto #Scam

  15. 📣🚨 A new and active #OkoBot malware campaign is abusing the ClickFix tactic and fake GitHub repos to trick users into installing fake browser extensions that steal personal and crypto wallet data.

    Listen to or read this news: hackread.com/okobot-malware-cl

    #CyberSecurity #Malware #ClickFix #Crypto #Scam

  16. 🛡️ uBlock Origin’s Chrome extension has quietly added protections against ClickFix by updating its badware filter list, blocking known sites used to trick users into copying & executing malicious commands. The rules also appear to cover uBlock Origin Lite. 🔒

    cyberinsider.com/ublock-origin #uBlockOrigin #Cybersecurity #Malware #ClickFix

    Appearently misleading check out the replies.

  17. RE: infosec.exchange/@betweentheha

    I recently encountered a ClickFix attack while visiting a trusted website. After reproducing it across multiple browsers, I realized the larger story isn’t just the malware, it’s how attackers are increasingly impersonating security mechanisms themselves.

    I wrote about the experience and what it means for users and organizations.

    betweenthehacks.com/blog/click

    #Cybersecurity #ClickFix #SocialEngineering

  18. A CAPTCHA should never ask you to open Terminal.

    I recently encountered a real ClickFix attack while visiting a trusted website. That experience led me to investigate why attackers are increasingly impersonating security itself instead of simply impersonating trusted brands.

    New Between The Hacks article:

    betweenthehacks.com/blog/click

    #ClickFix #Cybersecurity #InfoSec #SocialEngineering

  19. 🔎 Opera adds native protection against ClickFix scams

    #Opera now detects and blocks #ClickFix style social engineering pages before users can execute the malicious commands they display.

    🔗 read more: lifehacker.com/tech/opera-r...

    #ransomNews #cybersecurity

  20. 📣🚨 Fake Google and Cloudflare verification pages are being abused in new ClickFix campaigns that deliver seven malware families, including some of the most notorious infostealers seen in recent months.

    Listen or Read: hackread.com/clickfix-scam-goo

    #CyberSecurity #InfoSec #Malware #ClickFix #Infostealer