#clickfix

31 posts · Last used 8d

Compromised Ukrainian business sites are serving a fake Cloudflare CAPTCHA via hidden iframes. Clicking copies an msiexec command that victims are told to run via Windows Run, installing Psychedelic Stealer. Abuse of trusted sites and native binaries makes detection harder. #ClickFix #InfoStealer #Cloudflare #ThreatIntel https://cyberworldops.eu/en/fake-captcha-pushes-psychedelic-stealer-through-compromised-ukrainian
0
0
0
0
Brevo delivered ClickFix malware to 51 of its own customers Kirk at ADAMnetworks found Brevo serving ClickFix malware from its own infrastructure to 51 customer sites. I took part in the investigation using whack.sh. https://tuxxin.com/blog/brevo-clickfix-customer-sites #security #threatintelligence #whacksh #clickfix
0
0
0
0
ESET detections of #ClickFix doubled (+108%) between H2 2025 and H1 2026 as attackers expanded beyond fake CAPTCHAs to AI platforms (#AI-fix), browser extensions (#CrashFix), and cloud authentication workflows (#ConsentFix). In AI-fix attacks, attackers craft web pages that impersonate legitimate AI services, including #Anthropic Artifacts, #OpenAI Canvas, and Microsoft #Copilot Pages. The web pages display fake troubleshooting content designed to trick users into executing malicious commands. Another ClickFix evolution, CrashFix, operates in the browser environment through a fake ad blocker, causing fake browser crashes and displaying warnings of data loss to pressure victims into following malicious "quick fix" instructions. Finally, ConsentFix targets OAuth authorization tokens instead of passwords. Victims are tricked into handing over tokens that can provide access to Microsoft accounts without the need for credential theft. Read more about the evolution of ClickFix threat landscape in the latest #ESETThreatReport: https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-threat-report-h12026.pdf
2
0
2
0
🤖 UAC-0145 (Sandworm/GRU) uses ClickFix fake CAPTCHAs to trick Ukrainian targets into infecting themselves with data-stealing malware. Victims paste a PowerShell script from a fake verification page. Technical breakdown by CERT-UA. 🔗 https://thehackernews.com/2026/07/uac-0145-uses-clickfix-captchas-to.html #CyberSec #Malware #Sandworm #ClickFix #APT
0
0
0
0