The ClickFix attack method involves social engineering tactics to manipulate users into executing malicious commands. Typically, users are prompted by fake CAPTCHAs or error messages that guide them to copy and paste commands into their systems, resulting in malware installation.
Recent reports highlight the widespread use of ClickFix in various cyberattacks, affecting platforms like Microsoft 365 and targeting different user groups, including Mac and Windows users.
These attacks are effective because they exploit routine internet habits, such as solving CAPTCHAs or following on-screen instructions, to circumvent traditional security measures. Notable targets include Microsoft 365 accounts, where attackers gain unauthorized access by tricking users into harmful actions.
Researchers have documented campaigns targeting Microsoft 365 with this method, and incidents have also been reported involving malware distributed on platforms like social media ads posing as legitimate software.
The use of ClickFix represents an evolution in cybercrime, highlighting vulnerabilities in conventional security training and defenses. The method's ability to bypass security mechanisms without detectable files or exploits presents a novel challenge for cybersecurity professionals.
Organizations and individuals are urged to adapt by implementing advanced detection techniques and reinforcing user education to combat these evolving threats.
As ClickFix attacks continue to rise, there is an urgent need for new defensive strategies that focus on preventing the initial social engineering steps and increasing awareness among end-users about these types of cyber threats.
Microsoft and other security firms have started to issue guidance and best practices to help mitigate the risks associated with these attacks, emphasizing the importance of comprehensive cybersecurity measures.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The Russian state-sponsored threat actor Star Blizzard (also known as APT28 or Fancy Bear) has adopted a new malware installation technique called "RedFlick" to deploy its CosmicPulse backdoor. This method automates attacks and reduces victim interaction by using password-protected archives containing virtual disks with disguised LNK files, leading to the installation of multiple scheduled tasks and a downloader for the final payload.
Threat actors are using ChatGPT Custom GPTs to impersonate legitimate offerings and redirect users to malicious sites. These sites employ ClickFix lures to deliver malware, including remote access trojans (RATs), to at least 40 users. This activity marks a new method of abusing trusted AI platforms for malware distribution.
A Russian state-backed hacking group, Star Blizzard, has expanded its phishing operations this year, adopting a new mass-mailing platform and using compromised websites for attacks. This shift has led to over 100 organizations being affected, primarily in the U.S. and UK, indicating a broader targeting strategy beyond Ukraine.
Russian state-sponsored APT Star Blizzard has updated its attack methods, using a new infection chain called 'RedFlick' in recent spear-phishing campaigns. This technique, requiring single user interaction, delivers malware via password-protected archives and VHDX containers, impacting Ukrainian entities and international organizations supporting Ukraine.
A CSuite phishing campaign is targeting US organizations, combining Microsoft 365 session theft with the deployment of remote monitoring and management (RMM) tools. This dual approach allows attackers to gain persistent access to both business accounts and employee endpoints, escalating the potential impact of a phishing incident.
Russian state-sponsored hacking group Star Blizzard has targeted over 100 organizations, primarily in the U.S. and U.K., since January using fake event invitations to install the CosmicPulse backdoor on Windows computers. The group, linked to Russia's FSB, has evolved its tactics from using free email services and CAPTCHA pages to compromised WordPress/cPanel accounts and scheduled tasks for malware delivery.
Microsoft has analyzed NeedyMantis, a modular malware framework used by a China-based threat actor in targeted attacks against telecommunications and governmental organizations. This framework was deployed after initial compromise, indicating its use for maintaining long-term access and supporting follow-on operations.
Microsoft has identified NeedyMantis, a malware family used by hackers to maintain long-term access in breached networks, primarily targeting telecommunications, universities, and government contractors. The malware employs DLL sideloading with legitimate programs to establish command-and-control communication, allowing operators to deploy additional modules.
The JADEPUFFER threat actor, tracked by Microsoft as Storm-3168, conducted destructive operations in an Azure environment in early June 2026 by compromising service principals. This attack involved deleting various Azure resources, including Storage Accounts, SQL databases, and Virtual Machines, marking an evolution in the threat actor's methods.
The Lunex Stealer, distributed via compromised Ukrainian websites, utilizes a vulnerable AMD Radeon Software driver (CVE-2023-20598) to disable security tools and escalate privileges. This allows the malware to steal credentials and data from Chromium-based browsers and cryptocurrency wallets.
An active ClickFix campaign is compromising Ukrainian business websites to display fake Cloudflare verification pages. These pages trick visitors into downloading a new information stealer called Psychedelic, which harvests browser credentials, account tokens, and cryptocurrency data.
A new report by CTM360 details how ClickFix, a technique that tricks users into pasting malicious commands, has become the most common method for attackers to gain initial access to enterprise networks. This method bypasses traditional security measures like exploit detection, attachment scanning, and file reputation checks, posing a significant challenge for defenders.
A TeamFiltration campaign, UNK_CondorFiltration, targeted over 5,700 accounts across 28 Microsoft 365 tenants, primarily in Chilean retail and financial institutions. The campaign compromised seven unmanaged functional or service accounts that used default or unrotated passwords and lacked multi-factor authentication. This highlights a vulnerability in unmonitored non-human identities with weak credential practices.
A new Android malware-as-a-service (MaaS) platform named RemControl is actively targeting users in Europe, Canada, and the Middle East through malvertising campaigns impersonating the TVTap IPTV application. This malware utilizes phishing overlays to steal banking credentials and can perform various malicious actions by exploiting Accessibility Service permissions, posing a significant threat to mobile banking security in affected regions.
Cisco Talos identified new Windows malware, CLOSEDQUORUM, that uses up to four AI models (DeepSeek, Qwen, Mistral, Google Gemini) to vote on its next actions instead of a traditional command-and-control server. This marks the first documented Windows implant to delegate C2 decisions to AI models, changing how malware could operate autonomously.
Threat actors compromised legitimate MemTensor packages on npm and PyPI to distribute a Go-based credential stealer named sckit. This malware targets Windows, Linux, and macOS, collecting sensitive data from developer tools and cloud services, and exfiltrating it to an external server.
A Chinese threat actor, UTA0565, exploited a zero-day vulnerability chain in Google Chrome and Microsoft Windows to deploy CLEANGULP malware through fake websites. This attack chain, involving three vulnerabilities, allowed for remote code execution and targeted Asian government entities.
A Chinese-speaking threat actor exploited vulnerabilities in Zyxel GS1900 switches and WordPress Core (wp2shell) to steal sensitive data from government and small business entities. The attacks, detected by GreyNoise, resulted in the compromise of 996 devices and over 18,500 database records containing accounts, passwords, and PII.
Microsoft's Digital Crimes Unit, in coordination with law enforcement and other partners, disrupted the EvilTokens phishing-as-a-service (PhaaS) platform. This platform compromised over 12,000 Microsoft accounts across more than 10,000 organizations by exploiting device code authentication flows, enabling sophisticated business email compromise campaigns.
The SideCopy advanced persistent threat (APT) group has expanded its targeting in India to include academic institutions, moving beyond its historical focus on government entities. This shift indicates a broader scope for the Pakistan-linked group's intelligence gathering or disruption efforts, utilizing spear-phishing to deploy remote access trojans (RATs).
A North Korean threat actor group, known as the 'Contagious Interview' campaign, has compromised over 30,000 devices across 100+ countries and stolen $10.71 million in cryptocurrency from 7,000+ wallets. The group targets web designers, engineers, and cryptocurrency specialists by posing as recruiters on social media to initiate a multi-step malware infection.
Cybersecurity researchers have identified a new PowerShell backdoor, dubbed TASK#STOMP, which exfiltrates sensitive data including business documents, Wi-Fi passwords, and clipboard contents. This backdoor employs stealthy techniques like random file names, disguised scheduled tasks, and timestomping to evade detection and complicate forensic analysis. The discovery of TASK#STOMP highlights an ongoing threat to organizational data security, requiring vigilance in endpoint protection and incident response.
The Rust project issued a warning about an ongoing social engineering campaign targeting Rust-lang team members and popular crate owners. Attackers use fake job offers via video calls to trick targets into installing malicious software or executing code, aiming to hijack developer credentials and deploy malicious packages.
A new remote access trojan (RAT) named ChainScript is being distributed via ClickFix-like lures, employing Polygon smart contracts for command-and-control (C2) server discovery. This method allows threat actors to rotate their C2 infrastructure, complicating detection and takedown efforts.
The North Korean WaterPlum cyber group has infected over 30,000 devices in 100 countries by deploying malware during fake job interviews, compromising 7,000 cryptocurrency wallets and stealing $10.7 million. This operation uses persistent remote access trojans (RATs) and targets IT professionals, potentially using compromised devices as springboards into legitimate company networks.
A joint law enforcement advisory revealed that the North Korean hacking group WaterPlum compromised at least 30,000 devices globally between December 2025 and July 2026, transferring over $10.7 million in stolen cryptocurrency to North Korea. This activity highlights the ongoing financial motivations of state-sponsored hacking groups to fund national programs, impacting individuals and potentially their employers through intellectual property theft and espionage.
The Transparent Tribe threat group (APT36) is targeting government and defense entities in India and Afghanistan with new malware families, including a Rust-based backdoor named RUSTYSHADE. The group uses private GitHub repositories for command-and-control (C2) communications and typosquatted domains to host malicious scripts. This activity indicates an update in their tactics and tools for cyber espionage.
The cyberespionage group NightEagle, previously focused on China's high-tech sector, has expanded its operations to target Russian companies. The group uses stolen credentials, deploys the GhostContainer backdoor on Microsoft Exchange servers, and exploits Active Directory weaknesses to gain access and steal data.
Customer engagement platform Brevo experienced a supply chain attack that led to malicious code being injected into over 100,000 websites. Attackers exploited a vulnerability in Brevo's SAML SSO and later used a compromised Cloudflare API key to deploy a worker that injected malicious scripts, impacting customer websites and potentially leading to further compromises. This incident highlights the risks associated with third-party integrations and the potential for widespread impact from supply chain vulnerabilities.
North Korean hackers, identified as 'WaterPlum', infected over 30,000 devices across 100 countries and stole more than $10.5 million by targeting job seekers in the tech industry. The campaign uses fake job offers from AI or blockchain companies to trick applicants into downloading malware, allowing hackers to steal cryptocurrency and credentials.
A threat actor, CL-CRI-1171, operated a pay-per-install malware distribution service for at least two years, using YouTube and SEO poisoning to deliver malware like Docro Hijacker and Insomnia RAT. Separately, a campaign exploited 230 unauthenticated LocalAI instances exposed to the internet, leading to command execution with root privileges and data exfiltration, including AWS credentials.
Brevo confirmed a supply-chain attack where an attacker stole a Cloudflare API key and used it to inject malicious ClickFix scripts into Brevo's websites and customer-embedded JavaScript files. The attack, lasting approximately five and a half hours on September 14, affected pages on brevo.com and customer sites using Brevo components, distributing malware through a fake Cloudflare verification page.
The Iran-linked Handala Hack persona has been tied to HEAVYGRAM, a Telegram-based surveillance backdoor, and CRUDEEXCLUDE, a Delphi-based utility. These tools are used to exfiltrate data, capture screenshots, and establish persistence, primarily targeting Iranian dissidents and journalists.
The China-linked espionage group FamousSparrow has deployed a new backdoor, SparroWocky, in attacks targeting government organizations across Latin America for over a year. This new malware replaces their previous tool, SparrowDoor, and is designed to collect intelligence on Latin American governments' responses to U.S. pressure on Chinese economic interests.
An ongoing campaign is targeting Rust-lang members and owners of popular crates, attempting to compromise devices and accounts to publish malware. Attackers use video calls as a vector to trick targets into installing software or executing commands, posing as legitimate companies. This campaign follows similar attacks in June and a recent compromise of the `arrayref` crate.
Government agencies warn that Iranian state-linked hackers are deploying CHOSEN BRICK Windows malware to spy on dissidents, activists, and journalists globally. The malware steals communications, records audio, and exfiltrates data, posing a significant threat to targeted individuals.
Cloudflare's Client-Side Security machine learning model identified eight malicious JavaScript payloads on storefronts that traditional security scanning tools like VirusTotal and URLScan failed to detect. This highlights a gap in conventional security measures for client-side threats and demonstrates the effectiveness of behavioral analysis over signature-based detection.
A banking malware operation, active since mid-2025, uses a toolkit named KREMLIN to install malicious extensions in Chrome and Edge browsers without user approval. This technique bypasses Chromium's integrity checks, allowing the extensions to steal credentials, session tokens, and sensitive data. The malware's ability to circumvent browser security mechanisms represents a significant threat to user data integrity.
Kaspersky reports that three threat groups, NightEagle, Hacking Cat, and Toy Ghouls, are targeting Russian enterprises with various cyberattacks, including backdoors, ransomware, and wipers. This activity highlights ongoing cyber warfare and the evolving tactics used by state-sponsored or financially motivated threat actors against specific national targets.
The N0va phishkit is being used in campaigns targeting organizations across North America and Europe, impersonating trusted services to compromise legitimate authentication flows. Successful attacks grant threat actors access to sensitive data and business systems, leading to potential financial losses, operational disruption, and reputational damage.
A new Brazilian banking malware, KREMLIN, uses malicious browser extensions for Chrome and Edge to steal credentials and session tokens. The operation, tracked as REF9334, employs Ethereum smart contracts as dead drop resolvers to conceal its command-and-control infrastructure. This method allows the threat actor to dynamically update C2 endpoints and payload hosting locations, making disruption difficult.
Cybersecurity agencies from the US, UK, and Netherlands issued a joint advisory detailing Windows malware, named HEAVYGRAM or CHOSEN BRICK, used by Iran's intelligence service to spy on dissidents, journalists, and activists. The malware, controlled via Telegram, can exfiltrate data, record audio, and take screenshots, with collected information appearing on pro-Iranian leak sites.
Cybersecurity researchers have identified BambooToken, a new multi-platform malware active since February 2023, which uses the MQTT protocol for command and control of Windows and Linux systems. The malware has been observed in attacks targeting organizations in Asia and South America, with evidence suggesting a skilled threat actor. The initial access vector is currently unknown, but the malware uses Tendyron's 'OnKey' software for sideloading agents.
Multiple espionage groups are using a new exploit kit named BlueMoon, which chains together two Chrome zero-days (CVE-2026-85046, CVE-2026-87491) and one Windows zero-day (CVE-2026-85880). The kit was rapidly adopted by several China-linked threat actors, indicating a quick proliferation of sophisticated attack tools. This development highlights the ongoing threat from zero-day exploits and the speed at which they can be integrated into active campaigns.
Threat actors linked to groups like ShinyHunters are using passkey and single sign-on themed social engineering to compromise corporate Microsoft accounts and steal data from Microsoft 365 services. These attacks involve impersonating IT help desks to trick employees into signing into adversary-in-the-middle (AiTM) phishing sites or using device-code authentication flows, which capture credentials and session tokens.
Microsoft reports attackers are using invisible Unicode characters to bypass phishing filters, while a critical vulnerability in the WordPress Super Forms plugin is actively exploited. Additionally, the US offers a $10 million bounty for an Iranian cyber official, and CISA updates its insider threat guidance.
ClickFix attacks, which use compromised websites and fake CAPTCHAs to trick users into running malicious terminal commands, have become widespread, affecting both PC and Mac users. This technique exploits user fatigue with complex online interactions, leading to a surge in infections reported across platforms like Reddit.
Four malicious browser extensions for Chrome and Firefox were found stealing session tokens and wallet data from Axiom Trade and Padre users. Separately, a Chinese-speaking operator used AI agents to automate cyber intrusions against government and financial systems in multiple countries, exploiting known vulnerabilities.
Multiple cyber-espionage groups deployed the "BlueMoon" exploit kit, which chained zero-day vulnerabilities in Microsoft Windows and Google Chrome. This kit allows remote code execution, sandbox escape, and local privilege escalation, impacting users of Chromium-based browsers and Windows.
Security researchers identified an exploit kit, named BlueMoon, actively used by at least four hacking groups, some with ties to the Chinese government, to target critical vulnerabilities in Chromium-based browsers and older Windows versions. The kit chains together two Chromium vulnerabilities and one Windows kernel vulnerability, all of which have recently received patches, allowing attackers to install malware. This rapid deployment and sharing of a sophisticated exploit chain suggests a reduced barrier to entry for such capabilities, potentially due to AI-assisted vulnerability discovery and exploitation of the "patch gap" in open-source projects like Chromium.
Multiple espionage groups, including China-aligned APT31, used a new exploit kit called BlueMoon to chain vulnerabilities in Google Chrome and Microsoft Windows. This kit exploited "patch-gap" zero-days in Chrome and a Windows privilege escalation flaw to achieve code execution and download payloads.
Multiple Chinese cyber-espionage groups have been observed using the same Chrome zero-day exploit, dubbed "BlueMoon," to target U.S. defense contractors, NGOs, and Southeast Asian government agencies since late August. This shared exploit kit suggests a common supply source for offensive tools among otherwise separate hacking operations, highlighting a potential shift in the threat landscape and prompting Google to accelerate Chrome's security update cycle.
Barracuda has identified a new phishing technique that generates malicious pages as blob URLs within the victim's browser, rather than redirecting to a static external site. This method enhances stealth by bypassing traditional security detections for suspicious domains and external phishing pages. The development requires security teams to shift focus towards identity protection, browser security, and behavioral detection.
A new Linux rootkit is targeting F5 BIG-IP APM devices, intercepting PHP file loading to inject a fileless web shell directly into memory. This malware, identified as 'PoisonedRefresh' by ESET, is likely a second-stage payload deployed after exploiting a critical remote code execution flaw, CVE-2025-53521, in F5 BIG-IP APM systems.
Cybersecurity researchers have uncovered "BengalSEO," a campaign operating since 2015 that uses SEO poisoning on Microsoft Bing to distribute MayaBot malware and direct users to tech support scams. The campaign, linked to Indian IT service providers, leverages black hat SEO techniques to rank malicious lure pages high in search results, leading to malware deployment or scam call centers. This highlights the ongoing threat of SEO poisoning for malware distribution and financial fraud.
A new threat cluster, PREY-0058, is targeting Microsoft 365 and other SaaS platforms by impersonating IT help desk personnel to steal data and extort victims. This attack primarily targets executives through vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins, leading to credential harvesting and session replay attacks.
A phishing-as-a-service (PhaaS) framework named BigBear 2.0 bypassed multi-factor authentication (MFA) at 258 organizations, stealing over 5,000 Microsoft 365 credentials. The service uses an Evilginx2-based adversary-in-the-middle (AiTM) framework to intercept credentials and session cookies, enabling account hijacking.
North Korea-aligned threat actors are using a new Linux toolkit, including a custom HAProxy backdoor called 'ted backdoor' and trojanized utilities, to conduct long-term surveillance on South Korean automotive and media organizations. This toolkit enables remote command execution, credential harvesting, and web traffic injection, posing a significant threat to the targeted sectors' data security and operational integrity.
Cybersecurity firm Huntress has identified a worm-like attack campaign using modified ScreenConnect clients to spread malicious payloads to other endpoints. These attacks, which began in late August, leverage social engineering to install rogue ScreenConnect instances that then deploy VBScript files for reconnaissance, payload staging, and further propagation. This campaign highlights a new method for attackers to exploit remote access tools for lateral movement and persistence within networks.
Cybersecurity researchers have identified JSCeal, a V8 JavaScript malware capable of credential harvesting, surveillance, and traffic interception. This malware is distributed through malvertising campaigns impersonating trading platforms and can bypass Google authentication by stealing session cookies.
Threat actors are employing invisible Unicode characters to conceal phishing lures, a technique known as ASCII smuggling, to evade email security filters. Microsoft researchers observed a large-scale phishing campaign utilizing this method, which peaked at 2.37 million daily messages in February, demonstrating a new challenge for email security systems.
Elastic Security Labs identified four new programs associated with the REVSTEALER information stealer that disable Windows Update and Microsoft Defender to run a cryptocurrency miner. These modules, named ProManager, WinUpdate, SoftManager, and LockAppHost, persist on infected machines after the core stealer deletes itself, posing a continued threat.
A cybercriminal operation is using over 5,400 compromised WordPress and PrestaShop websites to deliver malicious payloads, initially ClickFix and later a WebRTC stager, stored in smart contracts on the BNB Smart Chain Testnet. This technique, known as EtherHiding, provides a resilient infrastructure for attackers by leveraging the blockchain for payload storage and modification, making takedowns difficult.
Microsoft's prompt injection detector identified a large-scale phishing campaign that uses invisible Unicode tag characters to bypass spam filters. Attackers insert these characters into financial keywords, making them undetectable by automated scanning systems while remaining invisible to human recipients. This technique highlights a vulnerability in how machines process text, affecting both traditional spam filters and potentially AI systems.
Microsoft has identified a high-volume phishing campaign that uses invisible Unicode tag characters to evade email filters. This technique, termed "ASCII Smuggling," splits financial lure words, preventing filters from parsing them correctly, and demonstrates how AI-era evasion tactics are being adapted for traditional phishing.
Rapid7 Labs discovered a previously undocumented Linux toolkit, named 'ted', embedded in trojanized HAProxy load balancers of two South Korean organizations. This backdoor intercepts web traffic, serves altered pages to specific visitors, and allows attackers to control the compromised systems without detection in standard logs. The toolkit's capabilities and stealth mechanisms pose a significant threat to organizations relying on HAProxy for load balancing, particularly given its attribution to state-sponsored actors.
Attackers compromised Coder's Cloudflare infrastructure, inserting unauthorized registry servers that distributed malicious Terraform modules containing credential-stealing code. This incident allowed the exfiltration of sensitive information, including API keys and CI/CD credentials, from a subset of Coder users.
Microsoft has issued a warning about a human-operated intrusion campaign that uses Microsoft Teams external collaboration to impersonate IT personnel, socially engineering users into granting remote access. This campaign, along with a related vishing operation called Spring Ring, allows attackers to install malicious software, perform reconnaissance, and pivot to high-value assets within targeted organizations. The attacks are significant because they leverage trusted communication platforms and social engineering to gain interactive access to internal infrastructure.
An active malware campaign is distributing malicious installers through fake software download websites, impersonating legitimate vendors. This campaign, attributed to the Chinese threat cluster Silver Fox, targets users looking for popular software, primarily affecting multinational organizations and Chinese-speaking users in China.
A cybercrime group named Gambling Goblin is installing malicious Apache modules on Brazilian government and educational web servers to redirect visitors to online gambling and sports betting sites. This campaign, tracked by Check Point Research since mid-2025, aims to manipulate search engine optimization by using high-reputation domains to inflate search rankings for betting platforms.
Phishing actors are misusing the Faronics Deploy endpoint management platform to gain remote administrative control over victim computers and subsequently install ScreenConnect remote support software. This attack vector allows threat actors to enroll victim machines into their Faronics deployment, execute scripts, and establish persistent remote access, posing a significant risk to targeted organizations.
The Iranian Nimbus Manticore hacking group is employing two new Node.js and JavaScript-based cross-platform remote access trojans (RATs), NodeRabbit and PollCat, delivered through fake coding challenges in spear-phishing attacks. This development expands the group's targeting capabilities to include Linux and macOS systems, marking an evolution in their malware arsenal and attack methods.
An Iran-linked cyberespionage group, Mirage Kitten, is targeting aviation, aerospace, and financial sector specialists with fake job offers to deploy new malware. The group uses NodeRabbit and PollCat malware, disguised as programming assignments, to gain remote access and collect information from victims' systems. This campaign affects developers in Egypt, Ethiopia, and Afghanistan, highlighting a new method of infiltration for cyber espionage.
Microsoft observed that the most common initial access method in the past year was ClickFix, a technique that social engineers users into pasting commands, accounting for 47% of attacks. This trend highlights that threat actors favor standardized, repeatable attack methods that scale efficiently over complex, novel exploits. This approach allows criminal groups to grow by consistently applying proven procedures against multiple targets.
Microsoft has identified a new ClickFix variant, TerminalFix, which uses fake Cloudflare CAPTCHA prompts to trick users into executing malicious PowerShell commands. This attack establishes a reverse tunnel into victims' internal networks, enabling potential lateral movement and data exfiltration, a departure from typical infostealer ClickFix campaigns.
The Silver Fox threat actor group is distributing the ValleyRAT backdoor by disguising it as signed Chinese adware, QN Wallpaper, and using DLL sideloading to execute the malware within a trusted process. This method allows the backdoor to bypass antivirus exclusions and gain full control of compromised machines, highlighting how adware can be exploited for more dangerous attacks.
Threat actors behind Aurora ransomware are using SpaceX's AI coding assistant, Cursor, to plan network attacks, according to CloudSEK and Gambit Security. This marks a new method for ransomware groups to strategize and execute cyberattacks, impacting organizations across multiple countries.
Multiple extensions for Google Chrome and Microsoft Edge were found to deliver a malware framework that stole cryptocurrency, sensitive data, and browser history. The malicious extensions, some acquired from original creators, injected scripts to hijack crypto wallets and exfiltrate user information, impacting tens of thousands of users.
Microsoft has identified a new malware variant, TerminalFix, that uses fake Cloudflare CAPTCHAs to trick users into executing malicious PowerShell commands in Windows Terminal. This attack deploys a sophisticated multi-stage backdoor that establishes persistent network-level proxy access and performs extensive Active Directory reconnaissance, posing a significant threat to organizational networks.
Cybersecurity researchers discovered 18 Google Chrome and one Microsoft Edge extensions containing code designed to steal wallet secrets and drain cryptocurrency. These extensions, active since February 2024, either started clean and were updated with malicious code or were acquired by threat actors.
Cybersecurity company ReliaQuest confirmed one of its employees was targeted in a social engineering attack involving a lookalike domain and fake SSO page, with the incident aligning with tactics used by ShinyHunters. Although the attacker gained brief view-only access to an identity dashboard, no applications, systems, or customer data were compromised. This incident highlights ongoing social engineering threats and the use of sophisticated impersonation tactics by groups like ShinyHunters.
A new cyberattack campaign is targeting individuals and organizations in Cambodia with Spark RAT, an open-source remote access trojan. The attackers use a vulnerable OPSWAT AppRemover driver to escalate privileges and disable security software, making the attacks harder to detect and mitigate.
Arctic Wolf identified GoCaracal, a new Go-based malware framework linked to Dark Caracal, which uses an Ethereum smart contract to retrieve replacement command-and-control (C2) addresses. This method provides a resilient C2 infrastructure for the malware, which offers remote shell access, data theft, and keylogging capabilities.
Cybersecurity researchers have identified new server infrastructure linked to the Iran-backed Tortoiseshell threat actor in Europe and the Middle East, suggesting an expansion of its operational reach. This expansion includes new malware samples and indicates the group is broadening its geographic targeting and capabilities beyond its previous focus on the Middle East and the United States.
A new adversary-in-the-middle (AitM) phishing toolkit named NovaCookies is being used to steal Microsoft 365 authentication sessions by redirecting sign-ins through attacker-controlled infrastructure. This service, available for $320/month, leverages genuine Docusign notifications to bypass security checks and has targeted hundreds of organizations globally.
A previously undocumented Windows backdoor named SLEEPWALKER has been discovered, which remains dormant in memory until activated by a specific network packet, then executes commands from its own 23-instruction language. This backdoor is designed for targeted operations as a post-compromise implant, making it difficult to detect with standard network monitoring tools.
The Mirage2FA phishing-as-a-service toolkit has affected over 4,500 companies, primarily in the US and EU, by exploiting Microsoft 365 login flows to bypass two-factor authentication and steal session cookies. This campaign creates significant identity-related risks, allowing attackers to access corporate email and sensitive data, and enabling impersonation and fraud.
Cybersecurity researchers found that websites are distributing Weedhack malware by impersonating Minecraft clients, using SEO poisoning and familiar platforms like Discord and MediaFire. The malware collects system information, sets Microsoft Defender exclusions, and steals sensitive data, impacting gamers who download these fake clients.
Cybersecurity researchers identified two new malware families, WordlistLoader and SynkLoader, used to deliver further payloads and potentially sell access to ransomware groups. WordlistLoader specifically delivers Amatera Stealer through ClearFake campaigns, which use the ClickFix technique to trick users into executing malicious commands. This development highlights evolving tactics in malware distribution, including the abuse of legitimate CDNs and blockchain for obfuscation.
Cybersecurity firms have reported on new and updated banking trojans, Manic, Grandoreiro, and ToxicPanda 2.0, which are actively targeting users worldwide. These malware variants are designed to steal credentials, sensitive data, and enable remote control of compromised devices for financial fraud. The continued evolution and global reach of these threats highlight the persistent danger of banking malware to individuals and financial institutions.
A new malware family named SynkLoader is being spread through Microsoft Teams phishing campaigns, impersonating IT help desks to steal credentials. This malware uses a fake lock screen to capture user passwords and can deploy various modules for system profiling, persistence, remote access, and traffic redirection. The campaign highlights an evolving threat vector targeting corporate environments via trusted communication platforms.
A new phishing toolkit, iAuthFlow V2, has emerged on cybercrime forums, offering persistent access to victim accounts even after password resets. This toolkit achieves this by silently adding a passkey during the initial phishing attack, allowing attackers to maintain access. The development of iAuthFlow V2 indicates an advancement in phishing techniques, making traditional recovery methods less effective.
Threat actors are exploiting FTP server banners to conceal commands that deploy two new remote access trojans (RATs), E4del and PINHOLE, on Windows systems. This novel technique allows malware to retrieve instructions from FTP greeting messages, making detection more challenging for security systems.
A hacker attempted to trick cybersecurity professionals into installing malware by posing as a crypto news site representative and using a fake conference lure through Google Docs. The campaign leveraged Google App Script to create a deceptive interface within a legitimate Google Doc, aiming to deliver infostealers or remote access tools.
A new Android malware named Manic combines banking fraud and spyware capabilities, targeting financial institutions, government services, and messaging applications in Ukraine, Russia, and Europe. This malware introduces a novel Wi-Fi mesh technique, allowing infected devices to relay data from offline phones through nearby compromised devices with internet access.
A new Android malware called Manic, active since February, combines spyware, banking fraud, and remote control capabilities, primarily targeting users in Ukraine and other European countries. This malware features an unusual data exfiltration mechanism that uses nearby compromised devices via Wi-Fi Direct or Bluetooth when a direct connection to its command-and-control server is unavailable. This capability allows data to be exfiltrated even from offline devices, posing a significant risk to user data security.
Socket Threat Research identified 40 malicious Mozilla Firefox extensions posing as Web3 products like OKX and Rabby Wallet to steal cryptocurrency wallet secrets. These extensions use various methods, including remote phishing and direct exfiltration of private keys, impacting users of Web3 services.
Huntress observed a 155x increase in password spraying attacks in the first half of 2026, with a significant campaign targeting Microsoft's Azure CLI. Attackers exploited the deprecated Resource Owner Password Credentials (ROPC) OAuth grant, which bypasses multi-factor authentication (MFA) configurations, leading to account compromises even in organizations with MFA policies.
Cybersecurity researchers have identified a global cybercrime operation, dubbed StopAndProtect, that uses almost 2,000 compromised WordPress sites to distribute malware, control infected systems, and store stolen data. This operation employs a toolkit of criminal software for various malicious activities, including ransomware deployment and data exfiltration.
Microsoft Defender Experts have identified and linked more than 30 web domains to the MacSync Stealer, a macOS information-stealing malware. This identification was made by correlating recurring endpoint and network behaviors across the malware's changing infrastructure, tracing its operations from payload retrieval to data exfiltration. This development provides a deeper understanding of the MacSync Stealer's operational infrastructure, aiding in better detection and mitigation strategies for macOS users and organizations.
Cybersecurity researchers have uncovered TWINLOOT, a new Python implant framework that uses trusted Microsoft services like SharePoint Online and Teams for command-and-control (C2) infrastructure. This framework allows attackers to steal Windows credentials, establish reverse SOCKS5 pivots, and execute arbitrary commands by mimicking legitimate network activity. The discovery highlights a sophisticated method for attackers to operate within enterprise environments undetected.
The Cavern command-and-control (C2) framework, used by Iranian state-sponsored hackers, has evolved to incorporate DNS A-record responses and Google Apps Script for communication, allowing it to blend with legitimate traffic. This development enables more sophisticated evasion techniques for the group targeting entities in Israel, making detection and mitigation more challenging for cybersecurity defenses.
A new macOS information-stealing malware, AmnesiaStealer, uses a streaming module to allow attackers to remotely control victims' web browsers and hijack authenticated sessions. This malware collects sensitive data from 16 Chromium-based browsers, including passwords, cryptocurrency wallets, and Apple Notes, and is distributed through ClickFix campaigns.
CTM360 researchers identified a large-scale phishing campaign using fake recruitment pages and Browser-in-the-Browser (BitB) techniques to steal Google and Facebook credentials, and relay MFA prompts. The campaign impersonated over 50 organizations and targeted marketing professionals, posing a risk to advertising platforms and corporate social media accounts.
A new Rust-based macOS information stealer, AmnesiaStealer, has been discovered in ClickFix attacks, distributed via a fake GitHub download page. This multi-stage malware harvests sensitive data, including keychains and browser information, and can remotely control browser sessions, posing a threat to macOS users.
The Jewelbug hacker group is performing espionage operations against government and military entities while simultaneously engaging in cryptocurrency fraud. Researchers discovered that both activities were managed from the same control panel, indicating a dual-purpose operation that combines state-sponsored objectives with financial cybercrime.
Cybersecurity researchers have identified AmnesiaStealer, a new Rust-based information stealer targeting macOS that can hijack Chromium web browser sessions. This malware allows attackers to gain interactive control over a victim's browser and exfiltrate sensitive data, posing a risk to macOS users' privacy and security.
The North Korean Lazarus Group exploited a newly patched Windows zero-day vulnerability (CVE-2026-68820) to deploy a new backdoor named Troy, targeting defense and aerospace companies in France, Germany, Brazil, and India. This activity is part of their ongoing Operation Dream Job, which uses social engineering and malicious PDF viewers to gain remote access and control over compromised systems.
North Korean hackers, identified as the Lazarus Group, have exploited a newly patched Windows zero-day vulnerability (CVE-2026-68820) to compromise systems in an ongoing campaign targeting the defense sector. This exploitation allows attackers to gain System privileges and deploy malware, posing a significant threat to affected organizations.
Two malicious versions of the LiteLLM library were briefly available on PyPI in March, containing code designed to steal cloud keys, SSH keys, Kubernetes tokens, and database passwords. CloudSEK has identified over 2,500 organizations potentially exposed based on a dataset of captured files, prompting a recommendation for affected parties to rotate credentials.
The DeadLock ransomware operation has adopted a decentralized infrastructure utilizing blockchain-backed services to maintain communication with victims and host data-leak activities. This approach enhances the ransomware's resistance to takedowns by law enforcement, as it reduces reliance on traditional, centralized web servers and domains.
The DeadLock ransomware group is using decentralized infrastructure, including Polygon smart contracts and the Session messaging network, to manage victim communications and data leak operations. This approach aims to make their extortion infrastructure more resilient and harder to disrupt. The use of blockchain technology by ransomware groups represents an evolving tactic to evade traditional countermeasures.
A threat actor, Storm-1175, previously linked to Medusa ransomware, is now using a new ransomware strain called StormEncryptor, often exploiting an authentication-bypass vulnerability (CVE-2026-18577) in the N-central remote monitoring and management (RMM) tool. This shift indicates a new threat for organizations, particularly those using self-hosted N-central servers, as the actor moves rapidly from initial access to data exfiltration and ransomware deployment.
Microsoft reports that Storm-1175, a China-linked threat actor, has deployed a new ransomware strain called StormEncryptor, shifting from its previous use of Medusa ransomware. This deployment likely exploits CVE-2026-18577, a newly disclosed N-able N-central vulnerability, which CISA has flagged as actively exploited. The new ransomware and exploitation method indicate an evolving threat landscape for organizations using N-able N-central and other internet-facing systems.
Microsoft Threat Intelligence reports that the China-linked group Storm-1175 is exploiting a critical vulnerability (CVE-2026-18577) in N-central, a remote monitoring and management (RMM) console, to deploy a new ransomware strain called StormEncryptor. This supply-chain attack allows attackers to gain full administrative control of N-central servers, potentially leading to widespread ransomware incidents across client networks managed by affected service providers.
A new macOS malware, delivered via ClickFix-style attacks, can steal browser passwords, iCloud Keychain data, and cached credentials, and uniquely, can incrementally drain cryptocurrency wallets. This marks the first observed instance of malware designed to siphon partial amounts from crypto wallets rather than the entire balance.
Gen Threat Labs identified two distinct attack campaigns in the first half of 2026 that exploited legitimate accounts, browser settings, and blockchain data to compromise victims. These campaigns highlight a shift towards attacks that do not rely on breaking trusted systems but rather on manipulating them from within, posing a challenge for traditional security measures.
A widespread email phishing campaign is actively using Adversary-in-the-Middle (AitM) techniques to compromise Microsoft 365 accounts, aiming to identify financial personnel and collect related email data. This campaign impacts organizations across multiple sectors in the U.S., Canada, and Europe, and shares tactics with previously identified Payroll Pirate attacks.
A new Go-based malware, delivered via ClickFix attacks, is targeting macOS users to steal cryptocurrency, browser passwords, and Apple Keychain data. This malware is notable for its ability to divert only a percentage of cryptocurrency transactions, rather than emptying entire wallets, making detection potentially more difficult.
Attackers exploited a SQL injection vulnerability in a Java application to install the khunt post-exploitation toolkit directly inside an Oracle database, enabling them to execute commands and steal credentials with SYSTEM-level permissions. This method of embedding a toolkit within the database itself, rather than deploying executables on the server, represents a novel technique for maintaining persistence and control within compromised corporate networks.
A macOS ClickFix operation, involving over 250 domains, now uses browser fingerprinting to selectively present malware lures to visitors. This server-side gate hides malicious pages from crawlers and sandboxes, delivering fake software downloads like MacSync and Atomic Stealer (AMOS) to specific Mac users. The change makes detection more difficult for security researchers and automated systems.
Threat actors are increasingly exploiting legitimate cloud services like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS to host phishing pages. This strategy allows them to evade detection due to the inherent trust in these platforms, free-tier offerings, and the ability to obscure their origin behind CDNs, making it harder for security teams to block malicious content without affecting legitimate users.
A multi-wave campaign, codenamed SMOKE#SCREEN, is using social engineering with fake Adobe and Zoom updates to install ConnectWise ScreenConnect, providing attackers with persistent remote access. This campaign highlights the increasing abuse of legitimate Remote Monitoring and Management (RMM) tools by threat actors to bypass security controls and maintain access.
Attackers compromised the GitHub account of the maintainer for the keyv library and other caching utilities, injecting a credential-stealing worm into numerous npm packages. This supply chain attack affected over 434 packages with a combined total of more than 2 billion monthly installs, posing a significant risk to developers and organizations using these dependencies.
A new Russian loader-as-a-service (LaaS) named DOUBLECUP is using ClickFix lures to embed malware-laced PNG images in browser caches, delivering CountLoader and a new remote access trojan called DeviceManager. This service provides operators with tools to create campaigns and load payloads, indicating a sophisticated new threat in the cybercrime landscape.
A new loader-as-a-service called DOUBLECUP uses ClickFix attacks to conceal malicious code within PNG images stored in victims' browser caches. This service delivers CountLoader to Windows and macOS, and a new remote access trojan named DeviceManager to Windows systems, posing a threat to users of various browsers.
Cybersecurity firm Bitdefender identified a malware campaign targeting Roblox players with fake installers for Xeno Executor, a popular script utility. These malicious installers deploy a Java-based Remote Access Trojan (RAT) and information stealer, compromising user data and accounts. This campaign highlights the risks associated with unofficial game utilities and the methods attackers use to distribute malware.
Cybersecurity researchers identified a new Go-based loader, HollowFrame, and a Rust-based backdoor, Matryoshka, used in a spear-phishing attack targeting a law firm. The attack chain involved a malicious LNK file, privilege escalation, weakening Microsoft Defender, and deploying additional payloads, providing attackers with persistent remote access and reconnaissance capabilities.
North Korean threat actors are employing a macOS malvertising campaign that uses fake system update screens to trick users into executing commands, leading to the deployment of cryptocurrency-stealing malware. This campaign, part of the Contagious Interview series, utilizes blockchain-hosted command-and-control infrastructure for resilience.
Threat actors are using Microsoft Teams vishing calls to impersonate IT support, gain remote access to corporate devices, and deploy Chaos ransomware in attacks primarily targeting North American organizations. This campaign, tracked as STAC4749 by Sophos, highlights an evolving social engineering tactic that bypasses traditional email-based phishing defenses, posing a significant risk to businesses.
Cybercrime groups are deploying new malware campaigns targeting Russia and CIS countries; xplogs22 uses phishing to deliver XWorm and LunaSpy, while Toy Ghouls uses custom GenieLocker ransomware. These campaigns highlight evolving threat actor tactics, including custom malware development and exploitation of trusted network access, which poses significant risks to organizations in the affected regions.
BlackFog researchers discovered MedusaHVNC, a remote access trojan (RAT) sold as malware-as-a-service, which utilizes hidden Windows desktops to operate invisibly to users. This technique allows the malware to leverage legitimate Windows functions for screen capture, input, and data exfiltration without detection, posing a significant threat to user privacy and data security.
A phishing campaign, dubbed Operation BlueDash, is using fake Microsoft Teams updates to deliver legitimate remote monitoring and management (RMM) tools like Level RMM and ConnectWise ScreenConnect. This campaign establishes persistent remote access and sets up redundant access points on compromised systems, posing a significant threat to organizational security.
Threat actors are using Steam discussion forums to spread XMRig cryptominers through 'ClickFix' social engineering attacks. These attacks trick users into running PowerShell commands that install malware disguised as system optimization tools, leading to unauthorized cryptocurrency mining on their devices.
A malvertising operation named SourTrade uses victims' browsers to construct malicious Windows executables from fragmented components, leveraging a legitimate Bun runtime. This technique allows the attackers to avoid serving a complete malicious file, making detection more difficult for traditional security measures.
A malvertising campaign targeting retail traders and crypto investors uses malicious JavaScript on fake webpages to assemble malware directly within the browser's memory. This technique makes detection more difficult as no complete malicious file is transmitted over the network, posing a challenge for security analysis.
The North Korean threat group BlueNoroff is using a phishing kit that impersonates Zoom to profile victims' cryptocurrency wallets before delivering malware. This campaign leverages compromised contacts and social engineering to target high-value individuals, creating a self-propagating attack chain.
Ukraine's CERT-UA has identified a new campaign by the Russia-aligned UAC-0099 threat group, which is distributing the MATCHBOIL.V2 malware through a fake Notepad++ plugin. This campaign uses phishing emails to deliver a ZIP archive containing a legitimate Notepad++ version bundled with a malicious DLL, establishing persistence and loading the updated malware loader.
A malvertising campaign on Bing Search is using a fake Claude desktop app installer, hosted on a legitimate Claude.ai domain, to deliver the SectopRAT malware. This operation, dubbed FakeAgent, compromised at least 29 organizations between July 21-22, deploying an info-stealing remote access trojan that targets sensitive user data.
Ukraine's CERT (CERT-UA) has identified a new campaign by threat cluster UAC-0099 that uses legitimate Notepad++ installations bundled with malicious plugins to establish persistence and deliver malware. This method exploits the normal plugin-loading mechanism of Notepad++ rather than a vulnerability, allowing for stealthy initial access, primarily targeting Ukrainian organizations.
Cisco Talos detailed msaRAT, a Rust implant used by the Chaos ransomware group, which routes command-and-control (C2) traffic through a victim's own headless Chrome or Edge browser using the Chrome DevTools Protocol and WebRTC. This method allows the ransomware to hide its C2 server address by making network traffic appear as legitimate browser activity to Cloudflare and Twilio services, complicating detection and blocking efforts.
The Chaos ransomware gang is using a new Rust-based malware, msaRAT, which routes command-and-control traffic through Chrome or Edge browsers. This technique uses the Chrome DevTools Protocol and headless browser sessions to evade detection by avoiding direct C2 connections.
The FakeGit operation has deployed SmartLoader and StealC malware via 7,600 malicious GitHub repositories. This tactic, labeled 'AgentBaiting', increases visibility to AI agents, enhancing the malware's distribution.
Researchers identified 7,600 malicious GitHub repositories in the FakeGit campaign, with over 800 masquerading as AI tools to distribute SmartLoader malware. This ongoing threat utilizes Social Engineering techniques to deceive both humans and AI agents, establishing persistence for further attacks.
A malware operator's unsecured server revealed a comprehensive phishing toolkit used in a WebDAV campaign targeting Windows users. The findings show the use of generative AI in crafting sophisticated phishing tactics, highlighting the evolving threat landscape in cybercrime.
Russian threat group UAC-0145 is employing ClickFix CAPTCHAs to distribute malware targeting Ukrainian devices. This attack method includes executing PowerShell commands and utilizing various malware types for data theft, highlighting a sophisticated cyber warfare tactic.
Microsoft has noted a rise in ACR Stealer malware attacks targeting enterprise customers, focusing on stealing sensitive data such as passwords and documents. The malware uses social engineering tactics and various delivery methods to infiltrate systems, indicating a serious threat to data security for affected organizations.
North Korean threat actors are using steganography in SVG images to conceal malware payloads in a campaign targeting software developers through fake job postings. This highlights an evolving method of attack aimed at stealing sensitive data and cryptocurrency, posing significant risks to the developer community.
The ACR Stealer infostealer is actively compromising enterprise networks by stealing sensitive data such as saved passwords and Microsoft 365 files. This rise in activity has been attributed to the use of ClickFix lures, prompting Microsoft to provide remediation guidance for affected organizations.
Russia's elite hacking group Sandworm is employing Clickfix to target sensitive organizations in Ukraine. This attack technique, which prompts users to input scripts through fake CAPTCHAs, is highly effective for installing malware and exfiltrating data.
Russian hackers from Sandworm have deployed fake CAPTCHA prompts on compromised websites to trick Ukrainians into installing malware. This technique, known as ClickFix, allows attackers to gain access to victim computers and deploy additional malicious tools.
A new malware called TELEPUZ is spreading through ClickFix lures since April 2026, executing PowerShell to steal sensitive data. Its lightweight, modular design and development suggest a malware-as-a-service model, raising concerns about its active evolution and potential widespread impact.
A Russian threat actor known as UAT-11795 has been deploying a new backdoor, Starland RAT, through trojanized installers of legitimate software, including WebEx and Zoom. These attacks, ongoing since June 2025, aim to steal credentials and cryptocurrency from users, primarily in the U.S., and involve complex infection methods and capabilities for data exfiltration.
Cybersecurity researchers discovered 292 fake GitHub repositories impersonating legitimate software to distribute infostealer malware. The malware collects sensitive data from web browsers, cryptocurrency wallets, and messaging applications, significantly impacting users who mistakenly download these malicious files.
Two new phishing kits, Jalisco and OmegaLord, target Microsoft 365 accounts, bypassing multi-factor authentication (MFA) through sophisticated techniques. These kits exploit OAuth 2.0 Device Authorization Grant flows, allowing attackers to access accounts without needing users' login credentials, posing significant risks to sensitive data.
A misconfigured server revealed three phishing operations targeting Microsoft 365, exposing vulnerabilities in the system. French security firm Lexfo tracked the campaigns leveraging Evilginx to bypass MFA, indicating significant security risks for corporate users.
A new malware campaign, SCMBANKER, targets Mexican banking customers using fake CAPTCHA pages to install malicious software. This threat poses significant risks as it enables attackers to monitor banking sessions and manipulate user actions.
Jamf Threat Labs reported a ClickFix-style attack using a sponsored ad on X that led to malware. The ad, masquerading as the legitimate app DynamicLake, redirected users to a malicious domain that prompted Terminal code input to install malware.
Attackers can hijack Microsoft 365 accounts in seconds using ClickFix and ConsentFix techniques. These methods exploit user habits with deceptive prompts and OAuth consent flows, allowing unauthorized access without traditional security interactions.
Research by Bert-Jan Pals details a new API-driven method for delivering malware via ClickFix, utilizing on-demand backend servers. This advancement allows attackers to distribute tailored malicious payloads that evade traditional detection methods, heightening security concerns for users and organizations.