Cybercriminals are leveraging ClickFix attacks in combination with the PySoxy proxy tool to maintain persistence on compromised systems. This tactic allows attackers to bypass traditional defenses and continue their…
In July 2026, a ClickFix campaign was discovered on the Artlist subdomain new-blog.artlist[.]io, where attackers injected malicious code that masqueraded as a CAPTCHA to install a Remote Access Trojan (RAT). The attack…
A ClickFix-style malware campaign was detected spreading through a sponsored ad on X, originating from a verified account. The ad masqueraded as the legitimate Mac app DynamicLake, leading users to a malicious domain,…
A new social engineering campaign named ClickFix has been identified, utilizing the Windows command-line tool finger.exe to install malware on users' systems. The attack initiates with a misleading CAPTCHA verification…
The ClickFix campaign has been identified as targeting the hospitality sector through fake booking reservation cancellations and fake Blue Screen of Death (BSOD) alerts. These tactics trick victims into executing…
Russian-linked cybercriminals are executing a ClickFix campaign aimed at European hotels and hospitality firms. Victims are receiving fake booking confirmations that deploy backdoors and infostealers onto their…
The EVALUSION and SmartApeSG campaigns are utilizing the ClickFix technique to deploy the Amatera Stealer and NetSupport Remote Access Trojan (RAT). These campaigns target various organizations, exploiting…
A new wave of ClickFix attacks is utilizing fake Windows Update screens to deceive users into executing malicious commands that install infostealing malware. These attacks employ steganography to hide malware within PNG…
The EVALUSION and SmartApeSG campaigns utilize the ClickFix technique to deploy the Amatera Stealer and NetSupport RAT. These campaigns target various organizations, leveraging vulnerabilities to execute malicious…
The ClickFix campaign exploits social engineering techniques to steal Facebook session tokens from users. By guiding victims through a fake verification process, attackers have successfully extracted live session…