Steam Forum ClickFix Installs XMRig Miner via PowerShell
Fake Steam forum fixes are installing an XMRig miner through PowerShell. Check…
UAC-0145 Uses Fake CAPTCHA and Security Apps Against Ukraine
CERT-UA says UAC-0145 is using ClickFix pages, fake security tools, Signal lures,…
ACR Stealer ClickFix Attacks: What to Check After Running the Command
Microsoft tracked ACR Stealer ClickFix chains using WebDAV, MSHTA and PowerShell. Check…
Potemkin Loader Turns ClickFix Into 11-Host Intrusion
A ClickFix command dropped Potemkin Loader, RMMProject and EtherRAT across 11+ hosts.…
Trojan:JS/Obfuse.NF!MTB: PowerShell Alert Keeps Coming Back
What Trojan:JS/Obfuse.NF!MTB means when Defender keeps catching hidden PowerShell, and how to…
Ghost CMS Exploit Poisons 700 Sites for ClickFix Malware
Attackers are exploiting Ghost CMS CVE-2026-26980 to inject ClickFix loaders into trusted…
Fake Chrome Update Virus: Terminal Opened
A fake Chrome update opened Terminal, PowerShell, Command Prompt, or Run? Learn…
KongTuke Uses Microsoft Teams Help-Desk Lures to Drop ModeloRAT
KongTuke moved from web-based ClickFix lures into external Microsoft Teams chats, using…
ClickFix WordPress Attacks Push Vidar Stealer Malware
Australia warns that ClickFix attacks are abusing compromised WordPress sites and fake…
AI Chats Are Delivering AMOS Stealer Through Google Search Results
Here's a novel malware delivery vector that nobody saw coming. Attackers are…
