Skip to content

Artlist ClickFix Campaign Uses Infostealer

Gbhackers •Mayura Kathir • July 15, 2026

A threat campaign discovered in mid-July 2026 abused the compromised Artlist subdomain new-blog. artlist[.]io to distribute a Remote Access Trojan through a fake CAPTCHA prompt. The operation combined stolen WordPress credentials, blockchain-based EtherHiding infrastructure, ClickFix social engineering, DLL side-loading, and a Tor-backed command-and-control fallback. The incident affected a high-value web property. Similarweb data indicates that […]

Extracted Entities

Attack Types (1)

Companies (1)

Domains (1)

Platforms (2)