All CosmicBytez Labs articles tagged #ClickFix, across news, security advisories, how-to guides, and projects.
A new ClickFix variant tricks victims into running PowerShell in Windows Terminal, sideloading a DLL that opens a persistent reverse-tunnel backdoor.
A new ClickFix variant, TerminalFix, tricks victims into running PowerShell via fake Cloudflare CAPTCHAs to install a stealthy reverse-tunnel implant.
Attackers published 24 npm packages using the unpkg CDN as malware hosting infrastructure, serving ClickFix CAPTCHA lures to steal credentials.
Two new malware loaders — WordlistLoader and SynkLoader — deliver ransomware-enabling payloads and steal Windows credentials via phishing.
Two new malware loaders target ransomware access brokering: WordlistLoader drops Amatera Stealer via ClickFix, SynkLoader harvests Windows credentials.
Security researchers expose WordlistLoader deploying Amatera stealer via ClickFix and SynkLoader delivering a 7-module RAT through Microsoft Teams phishing.
ESET's mid-2026 threat report reveals attackers adapting established techniques to AI platforms — deploying malicious AI skills, AI-assisted malware, record quishing activity, and ransomware tools engineered to defeat security software.
ESET's H1 2026 threat report reveals 3,000+ malicious AI skills in open repositories, a 108% ClickFix surge, record quishing activity, and the first Android malware to use generative AI at runtime.
This week's top threats: OpenAI's models escape a sealed test environment, a CVSS 9.3 Check Point flaw goes actively exploited, AI coding assistants hallucinate malicious packages, and ClickFix lures now abuse Claude chat links.
Threat actors are hijacking Steam discussion threads to pose as helpful community members, tricking frustrated gamers into running malicious PowerShell...
Group-IB researchers uncovered ClickLock, a macOS infostealer that runs a 210ms kill loop for up to 83 hours to coerce victims into entering their...
Russian state-sponsored threat actor UAC-0145 is deploying ClickFix-style fake CAPTCHA prompts to trick Ukrainian targets into self-installing...
Group-IB researchers discovered ClickLock, a new macOS infostealer distributed via ClickFix lures that terminates all visible system processes in a loop...
Group-IB researchers discovered ClickLock, a macOS infostealer that uses ClickFix social engineering to install a kill loop firing pkill every 210ms —...
A new banking fraud campaign tracked as REF6045 is deploying SCMBANKER malware through fake CAPTCHA ClickFix lures to steal credentials from customers of...
DragonForce hides C2 inside Microsoft Teams relay traffic; a SearchLeak attack weaponizes M365 Copilot for one-click data exfiltration; iRhythm confirms...
New analysis reveals the 'Lorem Ipsum' malware campaign has adopted ClickFix social engineering as its primary delivery mechanism, leveraging compromised...
The Axios HTTP client post-mortem reveals North Korean threat actors used a ClickFix-style fake Microsoft Teams error message to socially engineer a...
Researchers have identified DeepLoad, a previously undocumented malware loader that combines ClickFix social engineering with WMI-based persistence to...
A newly observed ClickFix campaign impersonates Cloudflare's CAPTCHA verification pages to deliver the Python-based Infiniti Stealer to macOS users via a...
A new info-stealing malware named Infinity Stealer is targeting macOS systems with a Python payload packaged as an executable using the open-source Nuitka...
The LeakNet ransomware gang is using ClickFix social engineering for initial access and a Deno-based malware loader to execute fileless payloads from...
Microsoft-tracked threat actor Velvet Tempest is deploying Termite ransomware via a ClickFix social-engineering chain that loads DonutLoader and installs...
Learn how to detect and prevent ClickFix social engineering attacks using EDR rules, network monitoring, YARA signatures, and endpoint hardening. Covers...
New IT offboarding checklist, endpoint security baseline, BGP monitoring guide, ClickFix detection guide, plus AI-powered attacks on FortiGate devices, a...
Microsoft discloses a new ClickFix variant that uses DNS nslookup commands to retrieve and execute malicious PowerShell payloads, marking the first known...
Threat actors are abusing publicly shared Claude AI artifacts and Google Ads to deliver the MacSync infostealer to macOS users through ClickFix social...
A sophisticated phishing campaign dubbed PHALT#BLYX is targeting European hospitality organizations with fake Booking.com cancellation emails that display...
North Korean threat actors are running sophisticated campaigns using AI-generated deepfake videos and the ClickFix social engineering technique to target...
UNC1069, a North Korean APT group, deployed a sophisticated ClickFix scam using a fake Zoom meeting to target a cryptocurrency executive in a social...