The ClickFix attack method involves social engineering tactics to manipulate users into executing malicious commands. Typically, users are prompted by fake CAPTCHAs or error messages that guide them to copy and paste commands into their systems, resulting in malware installation.
Recent reports highlight the widespread use of ClickFix in various cyberattacks, affecting platforms like Microsoft 365 and targeting different user groups, including Mac and Windows users.
These attacks are effective because they exploit routine internet habits, such as solving CAPTCHAs or following on-screen instructions, to circumvent traditional security measures. Notable targets include Microsoft 365 accounts, where attackers gain unauthorized access by tricking users into harmful actions.
Researchers have documented campaigns targeting Microsoft 365 with this method, and incidents have also been reported involving malware distributed on platforms like social media ads posing as legitimate software.
The use of ClickFix represents an evolution in cybercrime, highlighting vulnerabilities in conventional security training and defenses. The method's ability to bypass security mechanisms without detectable files or exploits presents a novel challenge for cybersecurity professionals.
Organizations and individuals are urged to adapt by implementing advanced detection techniques and reinforcing user education to combat these evolving threats.
As ClickFix attacks continue to rise, there is an urgent need for new defensive strategies that focus on preventing the initial social engineering steps and increasing awareness among end-users about these types of cyber threats.
Microsoft and other security firms have started to issue guidance and best practices to help mitigate the risks associated with these attacks, emphasizing the importance of comprehensive cybersecurity measures.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A new macOS information-stealing malware, AmnesiaStealer, uses a streaming module to allow attackers to remotely control victims' web browsers and hijack authenticated sessions. This malware collects sensitive data from 16 Chromium-based browsers, including passwords, cryptocurrency wallets, and Apple Notes, and is distributed through ClickFix campaigns.
CTM360 researchers identified a large-scale phishing campaign using fake recruitment pages and Browser-in-the-Browser (BitB) techniques to steal Google and Facebook credentials, and relay MFA prompts. The campaign impersonated over 50 organizations and targeted marketing professionals, posing a risk to advertising platforms and corporate social media accounts.
A new Rust-based macOS information stealer, AmnesiaStealer, has been discovered in ClickFix attacks, distributed via a fake GitHub download page. This multi-stage malware harvests sensitive data, including keychains and browser information, and can remotely control browser sessions, posing a threat to macOS users.
The Jewelbug hacker group is performing espionage operations against government and military entities while simultaneously engaging in cryptocurrency fraud. Researchers discovered that both activities were managed from the same control panel, indicating a dual-purpose operation that combines state-sponsored objectives with financial cybercrime.
Cybersecurity researchers have identified AmnesiaStealer, a new Rust-based information stealer targeting macOS that can hijack Chromium web browser sessions. This malware allows attackers to gain interactive control over a victim's browser and exfiltrate sensitive data, posing a risk to macOS users' privacy and security.
The North Korean Lazarus Group exploited a newly patched Windows zero-day vulnerability (CVE-2026-68820) to deploy a new backdoor named Troy, targeting defense and aerospace companies in France, Germany, Brazil, and India. This activity is part of their ongoing Operation Dream Job, which uses social engineering and malicious PDF viewers to gain remote access and control over compromised systems.
North Korean hackers, identified as the Lazarus Group, have exploited a newly patched Windows zero-day vulnerability (CVE-2026-68820) to compromise systems in an ongoing campaign targeting the defense sector. This exploitation allows attackers to gain System privileges and deploy malware, posing a significant threat to affected organizations.
Two malicious versions of the LiteLLM library were briefly available on PyPI in March, containing code designed to steal cloud keys, SSH keys, Kubernetes tokens, and database passwords. CloudSEK has identified over 2,500 organizations potentially exposed based on a dataset of captured files, prompting a recommendation for affected parties to rotate credentials.
The DeadLock ransomware operation has adopted a decentralized infrastructure utilizing blockchain-backed services to maintain communication with victims and host data-leak activities. This approach enhances the ransomware's resistance to takedowns by law enforcement, as it reduces reliance on traditional, centralized web servers and domains.
The DeadLock ransomware group is using decentralized infrastructure, including Polygon smart contracts and the Session messaging network, to manage victim communications and data leak operations. This approach aims to make their extortion infrastructure more resilient and harder to disrupt. The use of blockchain technology by ransomware groups represents an evolving tactic to evade traditional countermeasures.
A threat actor, Storm-1175, previously linked to Medusa ransomware, is now using a new ransomware strain called StormEncryptor, often exploiting an authentication-bypass vulnerability (CVE-2026-18577) in the N-central remote monitoring and management (RMM) tool. This shift indicates a new threat for organizations, particularly those using self-hosted N-central servers, as the actor moves rapidly from initial access to data exfiltration and ransomware deployment.
Microsoft reports that Storm-1175, a China-linked threat actor, has deployed a new ransomware strain called StormEncryptor, shifting from its previous use of Medusa ransomware. This deployment likely exploits CVE-2026-18577, a newly disclosed N-able N-central vulnerability, which CISA has flagged as actively exploited. The new ransomware and exploitation method indicate an evolving threat landscape for organizations using N-able N-central and other internet-facing systems.
Microsoft Threat Intelligence reports that the China-linked group Storm-1175 is exploiting a critical vulnerability (CVE-2026-18577) in N-central, a remote monitoring and management (RMM) console, to deploy a new ransomware strain called StormEncryptor. This supply-chain attack allows attackers to gain full administrative control of N-central servers, potentially leading to widespread ransomware incidents across client networks managed by affected service providers.
A new macOS malware, delivered via ClickFix-style attacks, can steal browser passwords, iCloud Keychain data, and cached credentials, and uniquely, can incrementally drain cryptocurrency wallets. This marks the first observed instance of malware designed to siphon partial amounts from crypto wallets rather than the entire balance.
Gen Threat Labs identified two distinct attack campaigns in the first half of 2026 that exploited legitimate accounts, browser settings, and blockchain data to compromise victims. These campaigns highlight a shift towards attacks that do not rely on breaking trusted systems but rather on manipulating them from within, posing a challenge for traditional security measures.
A widespread email phishing campaign is actively using Adversary-in-the-Middle (AitM) techniques to compromise Microsoft 365 accounts, aiming to identify financial personnel and collect related email data. This campaign impacts organizations across multiple sectors in the U.S., Canada, and Europe, and shares tactics with previously identified Payroll Pirate attacks.
A new Go-based malware, delivered via ClickFix attacks, is targeting macOS users to steal cryptocurrency, browser passwords, and Apple Keychain data. This malware is notable for its ability to divert only a percentage of cryptocurrency transactions, rather than emptying entire wallets, making detection potentially more difficult.
Attackers exploited a SQL injection vulnerability in a Java application to install the khunt post-exploitation toolkit directly inside an Oracle database, enabling them to execute commands and steal credentials with SYSTEM-level permissions. This method of embedding a toolkit within the database itself, rather than deploying executables on the server, represents a novel technique for maintaining persistence and control within compromised corporate networks.
A macOS ClickFix operation, involving over 250 domains, now uses browser fingerprinting to selectively present malware lures to visitors. This server-side gate hides malicious pages from crawlers and sandboxes, delivering fake software downloads like MacSync and Atomic Stealer (AMOS) to specific Mac users. The change makes detection more difficult for security researchers and automated systems.
Threat actors are increasingly exploiting legitimate cloud services like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS to host phishing pages. This strategy allows them to evade detection due to the inherent trust in these platforms, free-tier offerings, and the ability to obscure their origin behind CDNs, making it harder for security teams to block malicious content without affecting legitimate users.
A multi-wave campaign, codenamed SMOKE#SCREEN, is using social engineering with fake Adobe and Zoom updates to install ConnectWise ScreenConnect, providing attackers with persistent remote access. This campaign highlights the increasing abuse of legitimate Remote Monitoring and Management (RMM) tools by threat actors to bypass security controls and maintain access.
Attackers compromised the GitHub account of the maintainer for the keyv library and other caching utilities, injecting a credential-stealing worm into numerous npm packages. This supply chain attack affected over 434 packages with a combined total of more than 2 billion monthly installs, posing a significant risk to developers and organizations using these dependencies.
A new Russian loader-as-a-service (LaaS) named DOUBLECUP is using ClickFix lures to embed malware-laced PNG images in browser caches, delivering CountLoader and a new remote access trojan called DeviceManager. This service provides operators with tools to create campaigns and load payloads, indicating a sophisticated new threat in the cybercrime landscape.
A new loader-as-a-service called DOUBLECUP uses ClickFix attacks to conceal malicious code within PNG images stored in victims' browser caches. This service delivers CountLoader to Windows and macOS, and a new remote access trojan named DeviceManager to Windows systems, posing a threat to users of various browsers.
Cybersecurity firm Bitdefender identified a malware campaign targeting Roblox players with fake installers for Xeno Executor, a popular script utility. These malicious installers deploy a Java-based Remote Access Trojan (RAT) and information stealer, compromising user data and accounts. This campaign highlights the risks associated with unofficial game utilities and the methods attackers use to distribute malware.
Cybersecurity researchers identified a new Go-based loader, HollowFrame, and a Rust-based backdoor, Matryoshka, used in a spear-phishing attack targeting a law firm. The attack chain involved a malicious LNK file, privilege escalation, weakening Microsoft Defender, and deploying additional payloads, providing attackers with persistent remote access and reconnaissance capabilities.
North Korean threat actors are employing a macOS malvertising campaign that uses fake system update screens to trick users into executing commands, leading to the deployment of cryptocurrency-stealing malware. This campaign, part of the Contagious Interview series, utilizes blockchain-hosted command-and-control infrastructure for resilience.
Threat actors are using Microsoft Teams vishing calls to impersonate IT support, gain remote access to corporate devices, and deploy Chaos ransomware in attacks primarily targeting North American organizations. This campaign, tracked as STAC4749 by Sophos, highlights an evolving social engineering tactic that bypasses traditional email-based phishing defenses, posing a significant risk to businesses.
Cybercrime groups are deploying new malware campaigns targeting Russia and CIS countries; xplogs22 uses phishing to deliver XWorm and LunaSpy, while Toy Ghouls uses custom GenieLocker ransomware. These campaigns highlight evolving threat actor tactics, including custom malware development and exploitation of trusted network access, which poses significant risks to organizations in the affected regions.
BlackFog researchers discovered MedusaHVNC, a remote access trojan (RAT) sold as malware-as-a-service, which utilizes hidden Windows desktops to operate invisibly to users. This technique allows the malware to leverage legitimate Windows functions for screen capture, input, and data exfiltration without detection, posing a significant threat to user privacy and data security.
A phishing campaign, dubbed Operation BlueDash, is using fake Microsoft Teams updates to deliver legitimate remote monitoring and management (RMM) tools like Level RMM and ConnectWise ScreenConnect. This campaign establishes persistent remote access and sets up redundant access points on compromised systems, posing a significant threat to organizational security.
Threat actors are using Steam discussion forums to spread XMRig cryptominers through 'ClickFix' social engineering attacks. These attacks trick users into running PowerShell commands that install malware disguised as system optimization tools, leading to unauthorized cryptocurrency mining on their devices.
A malvertising operation named SourTrade uses victims' browsers to construct malicious Windows executables from fragmented components, leveraging a legitimate Bun runtime. This technique allows the attackers to avoid serving a complete malicious file, making detection more difficult for traditional security measures.
A malvertising campaign targeting retail traders and crypto investors uses malicious JavaScript on fake webpages to assemble malware directly within the browser's memory. This technique makes detection more difficult as no complete malicious file is transmitted over the network, posing a challenge for security analysis.
The North Korean threat group BlueNoroff is using a phishing kit that impersonates Zoom to profile victims' cryptocurrency wallets before delivering malware. This campaign leverages compromised contacts and social engineering to target high-value individuals, creating a self-propagating attack chain.
Ukraine's CERT-UA has identified a new campaign by the Russia-aligned UAC-0099 threat group, which is distributing the MATCHBOIL.V2 malware through a fake Notepad++ plugin. This campaign uses phishing emails to deliver a ZIP archive containing a legitimate Notepad++ version bundled with a malicious DLL, establishing persistence and loading the updated malware loader.
A malvertising campaign on Bing Search is using a fake Claude desktop app installer, hosted on a legitimate Claude.ai domain, to deliver the SectopRAT malware. This operation, dubbed FakeAgent, compromised at least 29 organizations between July 21-22, deploying an info-stealing remote access trojan that targets sensitive user data.
Ukraine's CERT (CERT-UA) has identified a new campaign by threat cluster UAC-0099 that uses legitimate Notepad++ installations bundled with malicious plugins to establish persistence and deliver malware. This method exploits the normal plugin-loading mechanism of Notepad++ rather than a vulnerability, allowing for stealthy initial access, primarily targeting Ukrainian organizations.
Cisco Talos detailed msaRAT, a Rust implant used by the Chaos ransomware group, which routes command-and-control (C2) traffic through a victim's own headless Chrome or Edge browser using the Chrome DevTools Protocol and WebRTC. This method allows the ransomware to hide its C2 server address by making network traffic appear as legitimate browser activity to Cloudflare and Twilio services, complicating detection and blocking efforts.
The Chaos ransomware gang is using a new Rust-based malware, msaRAT, which routes command-and-control traffic through Chrome or Edge browsers. This technique uses the Chrome DevTools Protocol and headless browser sessions to evade detection by avoiding direct C2 connections.
The FakeGit operation has deployed SmartLoader and StealC malware via 7,600 malicious GitHub repositories. This tactic, labeled 'AgentBaiting', increases visibility to AI agents, enhancing the malware's distribution.
Researchers identified 7,600 malicious GitHub repositories in the FakeGit campaign, with over 800 masquerading as AI tools to distribute SmartLoader malware. This ongoing threat utilizes Social Engineering techniques to deceive both humans and AI agents, establishing persistence for further attacks.
A malware operator's unsecured server revealed a comprehensive phishing toolkit used in a WebDAV campaign targeting Windows users. The findings show the use of generative AI in crafting sophisticated phishing tactics, highlighting the evolving threat landscape in cybercrime.
Russian threat group UAC-0145 is employing ClickFix CAPTCHAs to distribute malware targeting Ukrainian devices. This attack method includes executing PowerShell commands and utilizing various malware types for data theft, highlighting a sophisticated cyber warfare tactic.
Microsoft has noted a rise in ACR Stealer malware attacks targeting enterprise customers, focusing on stealing sensitive data such as passwords and documents. The malware uses social engineering tactics and various delivery methods to infiltrate systems, indicating a serious threat to data security for affected organizations.
North Korean threat actors are using steganography in SVG images to conceal malware payloads in a campaign targeting software developers through fake job postings. This highlights an evolving method of attack aimed at stealing sensitive data and cryptocurrency, posing significant risks to the developer community.
The ACR Stealer infostealer is actively compromising enterprise networks by stealing sensitive data such as saved passwords and Microsoft 365 files. This rise in activity has been attributed to the use of ClickFix lures, prompting Microsoft to provide remediation guidance for affected organizations.
Russia's elite hacking group Sandworm is employing Clickfix to target sensitive organizations in Ukraine. This attack technique, which prompts users to input scripts through fake CAPTCHAs, is highly effective for installing malware and exfiltrating data.
Russian hackers from Sandworm have deployed fake CAPTCHA prompts on compromised websites to trick Ukrainians into installing malware. This technique, known as ClickFix, allows attackers to gain access to victim computers and deploy additional malicious tools.
A new malware called TELEPUZ is spreading through ClickFix lures since April 2026, executing PowerShell to steal sensitive data. Its lightweight, modular design and development suggest a malware-as-a-service model, raising concerns about its active evolution and potential widespread impact.
A Russian threat actor known as UAT-11795 has been deploying a new backdoor, Starland RAT, through trojanized installers of legitimate software, including WebEx and Zoom. These attacks, ongoing since June 2025, aim to steal credentials and cryptocurrency from users, primarily in the U.S., and involve complex infection methods and capabilities for data exfiltration.
Cybersecurity researchers discovered 292 fake GitHub repositories impersonating legitimate software to distribute infostealer malware. The malware collects sensitive data from web browsers, cryptocurrency wallets, and messaging applications, significantly impacting users who mistakenly download these malicious files.
Two new phishing kits, Jalisco and OmegaLord, target Microsoft 365 accounts, bypassing multi-factor authentication (MFA) through sophisticated techniques. These kits exploit OAuth 2.0 Device Authorization Grant flows, allowing attackers to access accounts without needing users' login credentials, posing significant risks to sensitive data.
A misconfigured server revealed three phishing operations targeting Microsoft 365, exposing vulnerabilities in the system. French security firm Lexfo tracked the campaigns leveraging Evilginx to bypass MFA, indicating significant security risks for corporate users.
A new malware campaign, SCMBANKER, targets Mexican banking customers using fake CAPTCHA pages to install malicious software. This threat poses significant risks as it enables attackers to monitor banking sessions and manipulate user actions.
Jamf Threat Labs reported a ClickFix-style attack using a sponsored ad on X that led to malware. The ad, masquerading as the legitimate app DynamicLake, redirected users to a malicious domain that prompted Terminal code input to install malware.
Attackers can hijack Microsoft 365 accounts in seconds using ClickFix and ConsentFix techniques. These methods exploit user habits with deceptive prompts and OAuth consent flows, allowing unauthorized access without traditional security interactions.
Research by Bert-Jan Pals details a new API-driven method for delivering malware via ClickFix, utilizing on-demand backend servers. This advancement allows attackers to distribute tailored malicious payloads that evade traditional detection methods, heightening security concerns for users and organizations.