Tag

#ClickFix

32 stories taggedClickFix · page 2 of 3.

Security operations center wall showing multiple threat alerts simultaneously: an AI agent stepping outside guardrails, legacy vulnerability exploitation in tru
Threat Intelligence

Weekly Threat Recap: A Rogue AI Agent, Old Bugs Back at Work, and Exposed Systems Nobody Fixed

OpenAI reports an AI agent that stepped outside its lane, while attackers keep finding shelter in tools defenders already trust.

4 min read
Cyber-attack command center aesthetic with multiple monitors displaying fake Zoom and Microsoft Teams landing pages, cryptocurrency wallet monitoring tools, and
Threat Intelligence

North Korean Hackers Run Fake Zoom and Teams Sites to Rob Crypto Wallets

BlueNoroff's phishing kit screens visitors' crypto wallets before deciding who gets the malware, researchers say.

4 min read
A computer screen showing a fake software update or security warning pop-up window overlaying a browser interface, with cursor hovering near a suspicious downlo
Threat Intelligence

Microsoft Warns of Two ACR Stealer Campaigns Stealing Credentials Through Fake Fixes

Between late April and mid-June 2026, two separate criminal campaigns used a trick called ClickFix to persuade workers to hand over browser passwords, session tokens, and business documents, with no software flaw required.

3 min read
Illustration: a laptop screen in a dim office, showing a generic fake verification prompt with a highlighted keyboard
Threat Intelligence

Russian Military Hackers Trick Ukrainians Into Infecting Their Own PCs

Ukraine's cyber emergency team says a Sandworm sub-group is using fake CAPTCHA prompts to plant data-stealing malware.

3 min read
Illustration: a laptop screen showing a fake browser error dialog with a copy-paste instruction box, warm desk lamp light
Identity & Access

Microsoft sees spike in ACR Stealer attacks lifting passwords and session tokens from browsers

The info-stealer is arriving through fake 'fix this error' prompts and hidden inside JPEG images, and it walks off with the browser cookies that keep users signed in.

4 min read
Illustration: a laptop screen showing a generic fake browser error dialog
Threat Intelligence

ACR Stealer Tricks Staff Into Typing the Attack Themselves

Microsoft says a fake-fix trick is pushing a data thief onto business PCs, walking off with passwords, session cookies and cloud files.

4 min read
Illustration: a laptop screen showing a fake browser error dialog with a blurred instruction to press keyboard keys
Threat Intelligence

TELEPUZ: The New Malware Hiding Behind Fake 'Fix This' Website Pop-ups

A modular info-stealer is spreading through booby-trapped websites that trick visitors into pasting malicious commands into their own computers.

3 min read
A MacBook screen displaying a convincing popup dialog asking for password entry, with the background showing a locked desktop state, while the user's hand hover
Threat Intelligence

ClickLock Stealer Tricks Mac Users Into Handing Over Their Own Passwords

A newly discovered piece of Mac malware skips the usual hacking tricks and simply persuades victims to run it themselves, then locks the screen until they surrender their passwords.

3 min read
Illustration: a laptop screen showing a generic software installer progress bar in a dim home office, warm desk lamp glow
Threat Intelligence

Russian Crew Hides Starland Backdoor Inside Fake Zoom and WebEx Installers

UAT-11795 is spiking popular software downloads with a credential-and-crypto stealer, and US users are the main target.

4 min read
Illustration: a darkened office monitor displaying a generic fake CAPTCHA verification page reflected in a glass surface
Threat Intelligence

ClickFix: The Fake Error Pop-Up That Tricks You Into Hacking Yourself

A scam that launched in 2024 has grown into a thriving criminal marketplace. Researchers say standard antivirus tools are missing it almost entirely, and they have built a new detection method to fill the gap.

4 min read
Illustration: a laptop screen showing a generic blurred verification prompt with a checkbox, warm desk lamp light
Threat Intelligence

Fake CAPTCHA Pages Are Stealing From Mexican Bank Customers

Elastic Security Labs is tracking a fraud campaign, dubbed REF6045, that tricks people into pasting a malicious command from a bogus 'prove you're human' page.

3 min read
A computer screen displaying a fake error message with a prompt to paste a command, in an office environment
Threat Intelligence

ClickFix: Emerging Favorite for Cybercriminals in Malware Delivery

New ReliaQuest research shows ClickFix drove nearly 28% of defense-evasion activity between March and May 2026, and it's now hitting macOS for the first time.

3 min read
Illustration: a laptop screen showing a generic web browser with a red warning icon in the address bar and a blurred popup
Threat Intelligence

Opera's new Paste Protect tries to stop the copy-paste scam that's been draining wallets

The browser will now block dodgy commands before they reach your clipboard, targeting the ClickFix trick that has become criminals' favourite way to trick people into infecting their own computers.

3 min read
Illustration: a laptop screen showing a generic blurred cloud sign-in prompt
Identity & Access

Drag, Drop, Hijacked: How 'ConsentFix' Steals Microsoft 365 Sessions in Seconds

A new twist on the ClickFix trick turns Microsoft's own sign-in prompts into a session-theft machine, and a step-by-step guide is now circulating on a Russian crime forum.

4 min read
Illustration: a darkened office monitor displaying a generic fake CAPTCHA verification page reflected in a glass surface
Threat Intelligence

ClickFix Grows a Back Office: API-Served Payloads and a New AMSI Bypass

Researchers pulled roughly 3,000 live payloads from ClickFix infrastructure and found a polymorphic delivery pipeline built to defeat Windows script scanning.

3 min read
© 2026 Threat Vectr