#ClickFix
32 stories taggedClickFix.

The macOS ClickFix Scam Learned to Hide From Researchers
Microsoft says the fake-fix lure now checks your browser before showing itself, and a related campaign is pushing a new remote-control tool called ChainScript.

Criminals Are Hiding Malware Inside Trusted AI Tools Like Claude and ChatGPT
Attackers are abusing Claude Artifacts, shared ChatGPT links and sponsored search ads to slip malware past users who trust the branding.

A Government of India Website Is Tricking Visitors Into Running Malware From Their Own Keyboard
A fake security check on a page linked to India's STPI quietly loads a harmful command onto visitors' clipboards, then asks them to paste and run it themselves.

Hijacked HBO Max Reddit account pushed 108 malware ads in 48 hours
A verified account was used to run a copy-paste scam that infected Windows and Mac users with password stealers and crypto-wallet thieves.

Criminals Hid a Hacking Network Inside a Cryptocurrency Blockchain. Thirty-One Companies Got Caught.
A new campaign turns blockchain technology into an untraceable instruction relay, letting attackers redirect infected computers to a new server for less than a penny per update.

ClickFix: The Attack That Talks You Into Hacking Yourself
Microsoft says the fake 'prove you're not a robot' trick was the single most common way criminals broke into companies last year. The clever bit is that the victim does the hard work.

TerminalFix: The Fake CAPTCHA That Opens a Back Door Into Company Networks
Microsoft has spotted a new twist on the ClickFix scam that pushes victims to paste attacker commands straight into Windows Terminal, ending with a hidden tunnel into the internal network.

The Week in Identity: Router Backdoors, Off-Task AI Agents, and Login Kits for Sale
A weekly roundup of the dull-sounding defaults, forgotten bugs, and helpful chatbots that quietly handed attackers the keys this week.

WordlistLoader Hides Malware Inside Plain English Word Lists
A new delivery tool for a fast-growing password thief disguises harmful code as ordinary text, making it harder for security software to spot the infection before it takes hold.

Criminals Turn npm Into Free Hosting for Fake Cloudflare Login Traps
Researchers found 24 packages on the npm registry being used not to poison developers, but as free web hosting for phishing pages that pretend to be Cloudflare's human-check screen.

This Week's Security Grab Bag: AI Hijacks, Fake Fixes, and a Cursor Bug
A roundup week: nothing catastrophic on its own, but the patterns are the story.

Fake Mac Downloads Hide Behind 250+ Domains That Screen Visitors First
Microsoft says a large ClickFix network now checks who is knocking before showing macOS users a booby-trapped installer, keeping researchers and scanners out of view.

Russian hackers turn hotel Wi-Fi into a trap for Microsoft 365 logins
Microsoft has attributed the CaptiveCrunch campaign to Storm-2945, a sub-group of APT29, which has been poisoning hotel and conference Wi-Fi networks since at least May 2025 to steal corporate accounts using two newly identified malware families.

DOUBLECUP: the new Russian malware service that hides code inside cached images
A service called DOUBLECUP tricks users into pasting rogue commands, then pulls malware out of PNG files sitting in the browser's cache.

ESET report: criminals are teaching AI new tricks, and old malware new manners
The Slovak security firm's latest threat report says attackers are wiring AI assistants into their toolkits, dressing up scams as helpful pop-ups, and building ransomware that switches off the guards before it strikes.