Monday 14 September 2026 08:00:36 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContact
EnglishItaliano

#ClickFix


When npm Becomes a Phishing Host: The Mirror Abuse Behind ClickFix Lures

Published: 26 August 2026 10:25Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A cluster of malicious npm packages did not try to run code on install; instead, it appears to have turned package mirrors into a browser-facing trap for social engineering.

When a Package Registry Turns Into a Phishing Billboard

Published: 25 August 2026 17:08Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

Researchers identified 24 npm packages being used as distribution points for fake Cloudflare CAPTCHA pages, showing how trusted developer infrastructure can be repurposed for social engineering.

PavinLoader’s Quiet Trick: How a Trusted Build Tool Becomes a Malware Conveyor Belt

Published: 25 August 2026 12:40Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A multi-stage loader linked to fake installers, ClickFix lures, and game-themed packages shows how attackers can hide malicious activity inside ordinary Windows workflows.

PavinLoader Turns Verification Theater into a Stealer Delivery Chain

Published: 25 August 2026 12:06Category: Malware & BotnetsAuthor: SIGNALMONK

A .NET malware loader is being linked to ClickFix lures, fake download prompts, and malicious game campaigns, with blockchain-based C2 adding resilience to the campaign.

Fake Codex Pages Turn macOS Curiosity Into a Terminal Trap

Published: 25 August 2026 10:08Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A branded download lure and a copy-paste command prompt show how ClickFix-style abuse can turn everyday software searching into user-executed malware on macOS.

Two New Malware Loaders Target Windows Credentials

Published: 24 August 2026 16:27Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

WordlistLoader and SynkLoader are a reminder that criminal tooling often starts small, then hands off to stealer payloads and password theft.

When a CAPTCHA Becomes a Malware Loader: The macOS ClickFix Playbook Gets Harder to Kill

Published: 24 August 2026 10:20Category: Malware & BotnetsGeo: Asia / IndiaAuthor: NEXUSGUARDIAN

A macOS campaign tied to ClickFix-style lures shows how attackers can combine social engineering, blockchain-hosted infrastructure, and mixed payloads to make cleanup and disruption more difficult.

Browser Sessions Became the Prize: A macOS Stealer Turns Login State Into a Remote Weapon

Published: 24 August 2026 10:04Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

AmnesiaStealer points to a harsher reality for defenders: on modern browsers, stealing the session can matter more than stealing the password.

Fake CAPTCHA, Real Kernel Pressure: The Web Lure That Tries to Silence Security Tools

Published: 20 August 2026 15:03Category: Malware & BotnetsAuthor: NEXUSGUARDIAN

A layered Windows intrusion chain blends compromised WordPress pages, user-pasted PowerShell, and driver abuse to push a reported stealer payload past endpoint defenses.

Fake CAPTCHA, Real Damage: The ClickFix Playbook Learns to Muffle Endpoint Defenses

Published: 20 August 2026 14:19Category: Malware & BotnetsAuthor: SIGNALMONK

A new wave of lure pages and hand-entered PowerShell commands shows how attackers can turn ordinary verification prompts into a delivery path for defense-evasion malware.

Fake CAPTCHA, Real Malware: ClearFake’s Latest Chain Turns a Browser Check Into a Stealer Dropper

Published: 20 August 2026 12:53Category: Security Awareness & Social EngineeringAuthor: NEURALSHIELD

A ClearFake campaign reportedly folds a new intermediate loader, WordlistLoader, into a fake verification flow that ends with Amatera Stealer.

WordPress Front Doors Turned Into a Malware Relay

Published: 19 August 2026 08:04Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A campaign tied to compromised WordPress sites is being used to push deceptive CAPTCHA prompts and a mix of ransomware, credential theft, file theft, and remote monitoring claims.

Backdoor C2Looper Turns Legitimate Platforms Into a Stealthy Control Channel

Published: 18 August 2026 10:21Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

C2Looper is a July 2026 backdoor that researchers link, with caution, to ransomware-related activity and to a delivery path that may involve ClickFix chains.

Mac Browser Control Goes Live: Why AmnesiaStealer Changes the Shape of Session Theft

Published: 16 August 2026 18:13Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A newly identified macOS infostealer uses a ClickFix-style lure and a streaming module that can let an operator interact with the victim’s browser in real time.

Fake GitHub Doorway Leads to a Mac Stealer Built for Session Theft

Published: 14 August 2026 10:54Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A counterfeit download page and a ClickFix-style lure are at the center of a macOS infostealer case that spotlights a modern threat: turning a browser login into reusable access.

Fake GitHub Pages, Real Browser Theft: How a New macOS Infostealer Turns Trust Into Access

Published: 14 August 2026 08:20Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

AmnesiaStealer is being described as a macOS infostealer delivered through ClickFix-style lures, a reminder that on modern desktops the weakest link is often the person clicking the page.

One Prompt, One Loader, One Door Left Open

Published: 12 August 2026 08:16Category: Malware & BotnetsAuthor: IRONQUERY

A ClickFix-style lure can hand control to a modular loader chain and end with a persistent remote shell, turning user trust into operator access.

When a Website, a Browser Prompt, and a Blockchain Join the Same Malware Supply Chain

Published: 11 August 2026 14:30Category: Malware & BotnetsAuthor: SIGNALMONK

ErrTraffic appears to combine compromised WordPress pages, ClickFix-style social engineering, rotating delivery domains, and Polygon smart contracts into a layered route for Windows malware.

When Malware Stops Renting Servers and Starts Hiding in Code on the Chain

Published: 11 August 2026 10:07Category: Malware & BotnetsGeo: Asia / IndiaAuthor: NEXUSGUARDIAN

A reported MaaS campaign ties browser lures, user-driven execution, and Polygon smart contracts into a harder-to-trace delivery path.

Paste Once, Pay Later: How Blockchain Staging Is Reviving Old Malware Tricks

Published: 10 August 2026 14:22Category: Malware & BotnetsGeo: Europe / ItalyAuthor: NEXUSGUARDIAN

A recent ACN CSIRT Italia advisory points to a campaign that mixes ClickFix-style social engineering with EtherHiding on BNB Smart Chain, turning a simple copy-paste prompt into a delivery path for malicious code.