#ClickFix
27 stories taggedClickFix.

This Week's Security Grab Bag: AI Hijacks, Fake Fixes, and a Cursor Bug
A roundup week: nothing catastrophic on its own, but the patterns are the story.

Fake Mac Downloads Hide Behind 250+ Domains That Screen Visitors First
Microsoft says a large ClickFix network now checks who is knocking before showing macOS users a booby-trapped installer, keeping researchers and scanners out of view.

Russian hackers turn hotel Wi-Fi into a trap for Microsoft 365 logins
Microsoft says APT29 sub-group Storm-2945 has been hijacking guest Wi-Fi at hotels and conference centres since May, planting two new malware families to steal corporate accounts.

DOUBLECUP: the new Russian malware service that hides code inside cached images
A service called DOUBLECUP tricks users into pasting rogue commands, then pulls malware out of PNG files sitting in the browser's cache.

ESET report: criminals are teaching AI new tricks, and old malware new manners
The Slovak security firm's latest threat report says attackers are wiring AI assistants into their toolkits, dressing up scams as helpful pop-ups, and building ransomware that switches off the guards before it strikes.

Weekly Threat Recap: A Rogue AI Agent, Old Bugs Back at Work, and Exposed Systems Nobody Fixed
OpenAI reports an AI agent that stepped outside its lane, while attackers keep finding shelter in tools defenders already trust.

North Korean Hackers Run Fake Zoom and Teams Sites to Rob Crypto Wallets
BlueNoroff's phishing kit screens visitors' crypto wallets before deciding who gets the malware, researchers say.

Microsoft Warns of Two ACR Stealer Campaigns Stealing Credentials Through Fake Fixes
Between late April and mid-June 2026, two separate criminal campaigns used a trick called ClickFix to persuade workers to hand over browser passwords, session tokens, and business documents, with no software flaw required.

Russian Military Hackers Trick Ukrainians Into Infecting Their Own PCs
Ukraine's cyber emergency team says a Sandworm sub-group is using fake CAPTCHA prompts to plant data-stealing malware.

Microsoft sees spike in ACR Stealer attacks lifting passwords and session tokens from browsers
The info-stealer is arriving through fake 'fix this error' prompts and hidden inside JPEG images, and it walks off with the browser cookies that keep users signed in.

ACR Stealer Tricks Staff Into Typing the Attack Themselves
Microsoft says a fake-fix trick is pushing a data thief onto business PCs, walking off with passwords, session cookies and cloud files.

ClickLock: the Mac malware that locks up your screen until you type your password
A new macOS stealer, tracked by Group-IB, freezes everything on the screen except a password box. It has already hit around 100 machines in 33 countries.

TELEPUZ: The New Malware Hiding Behind Fake 'Fix This' Website Pop-ups
A modular info-stealer is spreading through booby-trapped websites that trick visitors into pasting malicious commands into their own computers.

ClickLock Stealer Tricks Mac Users Into Handing Over Their Own Passwords
A newly discovered piece of Mac malware skips the usual hacking tricks and simply persuades victims to run it themselves, then locks the screen until they surrender their passwords.

Russian Crew Hides Starland Backdoor Inside Fake Zoom and WebEx Installers
UAT-11795 is spiking popular software downloads with a credential-and-crypto stealer, and US users are the main target.