home.social

#pastejacking — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #pastejacking, aggregated by home.social.

  1. 2025-04-22 (Tuesday): Always fun to find the fake CAPTCHA pages with the #ClickFix style instructions trying to convince viewers to infect their computers with malware.

    Saw #StealC from an infection today.

    Indicators available at github.com/malware-traffic/ind

    #ClipboardHijacking #Pastejacking

  2. 2025-04-22 (Tuesday): Always fun to find the fake CAPTCHA pages with the #ClickFix style instructions trying to convince viewers to infect their computers with malware.

    Saw #StealC from an infection today.

    Indicators available at github.com/malware-traffic/ind

    #ClipboardHijacking #Pastejacking

  3. 2025-04-22 (Tuesday): Always fun to find the fake CAPTCHA pages with the #ClickFix style instructions trying to convince viewers to infect their computers with malware.

    Saw #StealC from an infection today.

    Indicators available at github.com/malware-traffic/ind

    #ClipboardHijacking #Pastejacking

  4. 2025-04-22 (Tuesday): Always fun to find the fake CAPTCHA pages with the #ClickFix style instructions trying to convince viewers to infect their computers with malware.

    Saw #StealC from an infection today.

    Indicators available at github.com/malware-traffic/ind

    #ClipboardHijacking #Pastejacking

  5. 2025-04-22 (Tuesday): Always fun to find the fake CAPTCHA pages with the #ClickFix style instructions trying to convince viewers to infect their computers with malware.

    Saw #StealC from an infection today.

    Indicators available at github.com/malware-traffic/ind

    #ClipboardHijacking #Pastejacking

  6. Social media post I wrote for my employer on other platforms.

    2025-04-04 (Friday): Injected #KongTuke script in pages from legitimate but compromised websites leads to fake #CAPTCHA style pages and #ClipboardHijacking (#pastejacking). These pages ask users to paste script into a Run window. Latest info at

    Information from an infection run earlier today at github.com/PaloAltoNetworks/Un

    Of note, we can find legitimate websites with the injected hashtag#KongTuke script by pivoting on the KongTuke domain in URLscan:

    urlscan.io/search/#lancasternh

  7. Social media post I wrote for my employer on other platforms.

    2025-04-04 (Friday): Injected #KongTuke script in pages from legitimate but compromised websites leads to fake #CAPTCHA style pages and #ClipboardHijacking (#pastejacking). These pages ask users to paste script into a Run window. Latest info at

    Information from an infection run earlier today at github.com/PaloAltoNetworks/Un

    Of note, we can find legitimate websites with the injected hashtag#KongTuke script by pivoting on the KongTuke domain in URLscan:

    urlscan.io/search/#lancasternh

  8. Social media post I wrote for my employer on other platforms.

    2025-04-04 (Friday): Injected #KongTuke script in pages from legitimate but compromised websites leads to fake #CAPTCHA style pages and #ClipboardHijacking (#pastejacking). These pages ask users to paste script into a Run window. Latest info at

    Information from an infection run earlier today at github.com/PaloAltoNetworks/Un

    Of note, we can find legitimate websites with the injected hashtag#KongTuke script by pivoting on the KongTuke domain in URLscan:

    urlscan.io/search/#lancasternh

  9. Social media post I wrote for my employer on other platforms.

    2025-04-04 (Friday): Injected #KongTuke script in pages from legitimate but compromised websites leads to fake #CAPTCHA style pages and #ClipboardHijacking (#pastejacking). These pages ask users to paste script into a Run window. Latest info at

    Information from an infection run earlier today at github.com/PaloAltoNetworks/Un

    Of note, we can find legitimate websites with the injected hashtag#KongTuke script by pivoting on the KongTuke domain in URLscan:

    urlscan.io/search/#lancasternh

  10. Social media post I wrote for my employer on other platforms.

    2025-04-04 (Friday): Injected #KongTuke script in pages from legitimate but compromised websites leads to fake #CAPTCHA style pages and #ClipboardHijacking (#pastejacking). These pages ask users to paste script into a Run window. Latest info at

    Information from an infection run earlier today at github.com/PaloAltoNetworks/Un

    Of note, we can find legitimate websites with the injected hashtag#KongTuke script by pivoting on the KongTuke domain in URLscan:

    urlscan.io/search/#lancasternh