Tag

#ClickFix

32 stories taggedClickFix.

Illustration: a modern silver laptop on a dark desk
Threat Intelligence

The macOS ClickFix Scam Learned to Hide From Researchers

Microsoft says the fake-fix lure now checks your browser before showing itself, and a related campaign is pushing a new remote-control tool called ChainScript.

4 min read
A split-screen view showing trusted application interfaces on one side morphing into malicious code structures on the other, with download progress indicators v
AI Security

Criminals Are Hiding Malware Inside Trusted AI Tools Like Claude and ChatGPT

Attackers are abusing Claude Artifacts, shared ChatGPT links and sponsored search ads to slip malware past users who trust the branding.

4 min read
A laptop screen displaying a government website with a fake security warning popup, a command-line interface or paste dialog visible, with a keyboard in the for
Threat Intelligence

A Government of India Website Is Tricking Visitors Into Running Malware From Their Own Keyboard

A fake security check on a page linked to India's STPI quietly loads a harmful command onto visitors' clipboards, then asks them to paste and run it themselves.

4 min read
A Reddit thread from a verified entertainment account flooded with copy-pasted scam messages, Windows and Mac malware warning popups appearing in separate brows
Threat Intelligence

Hijacked HBO Max Reddit account pushed 108 malware ads in 48 hours

A verified account was used to run a copy-paste scam that infected Windows and Mac users with password stealers and crypto-wallet thieves.

4 min read
A blockchain network visualization displayed across multiple monitors in a security research lab, with hidden command-and-control instructions embedded within t
Threat Intelligence

Criminals Hid a Hacking Network Inside a Cryptocurrency Blockchain. Thirty-One Companies Got Caught.

A new campaign turns blockchain technology into an untraceable instruction relay, letting attackers redirect infected computers to a new server for less than a penny per update.

5 min read
A laptop screen showing a convincing fake captcha verification popup while a user's finger hovers near the keyboard, office background blurred, moment of social
Threat Intelligence

ClickFix: The Attack That Talks You Into Hacking Yourself

Microsoft says the fake 'prove you're not a robot' trick was the single most common way criminals broke into companies last year. The clever bit is that the victim does the hard work.

4 min read
A Windows Terminal window open on a user's screen displaying a spoofed CAPTCHA popup above it, malicious command strings visible in the terminal ready to be pas
Threat Intelligence

TerminalFix: The Fake CAPTCHA That Opens a Back Door Into Company Networks

Microsoft has spotted a new twist on the ClickFix scam that pushes victims to paste attacker commands straight into Windows Terminal, ending with a hidden tunnel into the internal network.

4 min read
Close-up of a router's ethernet ports glowing with activity lights, a single red warning indicator blinking among the green, dust settling on the device's venti
Threat Intelligence

The Week in Identity: Router Backdoors, Off-Task AI Agents, and Login Kits for Sale

A weekly roundup of the dull-sounding defaults, forgotten bugs, and helpful chatbots that quietly handed attackers the keys this week.

4 min read
A text editor displaying seemingly innocent English word lists and passages, with hidden malware code visualized as faint glitching text beneath the surface, su
Threat Intelligence

WordlistLoader Hides Malware Inside Plain English Word Lists

A new delivery tool for a fast-growing password thief disguises harmful code as ordinary text, making it harder for security software to spot the infection before it takes hold.

3 min read
A developer's workspace with an npm package manager interface open on the monitor, showing package listings and download counts, with a phishing login page prev
Threat Intelligence

Criminals Turn npm Into Free Hosting for Fake Cloudflare Login Traps

Researchers found 24 packages on the npm registry being used not to poison developers, but as free web hosting for phishing pages that pretend to be Cloudflare's human-check screen.

3 min read
A busy security operations center wall displaying multiple stacked windows and alerts from different security tools, creating a complex layered visual of interc
Threat Intelligence

This Week's Security Grab Bag: AI Hijacks, Fake Fixes, and a Cursor Bug

A roundup week: nothing catastrophic on its own, but the patterns are the story.

4 min read
A browser window showing a fake macOS download page with a security warning overlay and multiple domain names partially visible in the address bar or browser ta
Threat Intelligence

Fake Mac Downloads Hide Behind 250+ Domains That Screen Visitors First

Microsoft says a large ClickFix network now checks who is knocking before showing macOS users a booby-trapped installer, keeping researchers and scanners out of view.

3 min read
A hotel lobby with Wi-Fi router and network infrastructure visible, guests at tables with laptops and phones connecting to wireless networks, login screens glow
Identity & Access

Russian hackers turn hotel Wi-Fi into a trap for Microsoft 365 logins

Microsoft has attributed the CaptiveCrunch campaign to Storm-2945, a sub-group of APT29, which has been poisoning hotel and conference Wi-Fi networks since at least May 2025 to steal corporate accounts using two newly identified malware families.

4 min read
Computer screen showing browser cache folder with PNG image files, malware analysis software running in background, code and command-line interfaces visible wit
Threat Intelligence

DOUBLECUP: the new Russian malware service that hides code inside cached images

A service called DOUBLECUP tricks users into pasting rogue commands, then pulls malware out of PNG files sitting in the browser's cache.

3 min read
A hacker's workspace with AI chatbot interface running on one monitor, malware code editor on another, pop-up windows mimicking legitimate software alerts scatt
Threat Intelligence

ESET report: criminals are teaching AI new tricks, and old malware new manners

The Slovak security firm's latest threat report says attackers are wiring AI assistants into their toolkits, dressing up scams as helpful pop-ups, and building ransomware that switches off the guards before it strikes.

3 min read
© 2026 Threat Vectr