A campaign tied to compromised WordPress sites is being used to push deceptive CAPTCHA prompts and a mix of ransomware, credential theft, file theft, and remote monitoring claims.
C2Looper is a July 2026 backdoor that researchers link, with caution, to ransomware-related activity and to a delivery path that may involve ClickFix chains.
A newly identified macOS infostealer uses a ClickFix-style lure and a streaming module that can let an operator interact with the victim’s browser in real time.
A counterfeit download page and a ClickFix-style lure are at the center of a macOS infostealer case that spotlights a modern threat: turning a browser login into reusable access.
AmnesiaStealer is being described as a macOS infostealer delivered through ClickFix-style lures, a reminder that on modern desktops the weakest link is often the person clicking the page.
A ClickFix-style lure can hand control to a modular loader chain and end with a persistent remote shell, turning user trust into operator access.
ErrTraffic appears to combine compromised WordPress pages, ClickFix-style social engineering, rotating delivery domains, and Polygon smart contracts into a layered route for Windows malware.
A reported MaaS campaign ties browser lures, user-driven execution, and Polygon smart contracts into a harder-to-trace delivery path.
A recent ACN CSIRT Italia advisory points to a campaign that mixes ClickFix-style social engineering with EtherHiding on BNB Smart Chain, turning a simple copy-paste prompt into a delivery path for malicious code.
A social-engineering chain is turning user trust into code execution, then targeting the secrets that make account takeover and crypto theft possible.
A social-engineering chain aimed at selected Mac users pairs fake download pages with browser fingerprinting and Terminal-pasted commands, with Atomic Stealer as the suspected endgame.
A large cluster of lookalike download domains is being used to selectively serve macOS users infostealer payloads, with the lure hidden behind browser fingerprinting and ClickFix-style social engineering.
A ClickFix lure, a PNG in browser cache, and a loader chain to CountLoader and DeviceManager show how attackers are mixing social engineering with ordinary web mechanics.
Cloned repositories, infostealers, and social-engineering lures are turning routine AI setup work into a path to cloud credential theft.
A threat report points to attackers folding AI abuse, QR lures, and defensive evasion into a more adaptable playbook.
A ClickFix-style lure, EtherHiding infrastructure, and a reported DPRK-linked wallet trail show how one operation can blend social engineering, resilient delivery, and on-chain tracing.
Attackers are using fake CAPTCHAs to trick macOS users into running malicious commands, in a campaign that reportedly deploys AMOS and targets browser credentials and crypto wallets.
ClickFix turns a routine trust moment into the attack, using fake verification prompts to push macOS users toward malware installation without a software bug.
A cluster of topics around rogue AI agents, a Check Point exploit, slopsquatting, and ClickFix lures points to one hard truth: attackers keep aiming at trust boundaries, not just code flaws.
A support-seeking gamer can become the execution step in a ClickFix lure, turning a forum reply into a path for XMRig and silent resource theft.