Tag: ClickFix

HBO Max Reddit Ads Led to the PasteSwitch Malware Operation

A hijacked HBO Max Reddit account ran 108 malicious ads. Researchers followed…

Daniel Zimmermann

SimpleSwap Bonus Script Scam: Remove Malicious Userscripts

Remove a fake SimpleSwap bonus userscript, check browser persistence, and respond safely…

Daniel Zimmermann

StopAndProtect Turns Hacked WordPress Sites Into Malware Traps

StopAndProtect uses hacked WordPress sites, fake CAPTCHA prompts, and PowerShell. Follow the…

Brendan Smith

TerminalFix Turns Fake CAPTCHA Into a Network Tunnel

Microsoft says TerminalFix uses a fake CAPTCHA, PowerShell, DLL sideloading, and a…

Brendan Smith

PavinLoader Spreads Through ClickFix and Fake Downloads

PavinLoader links fake CAPTCHA, software, and game lures to a multi-stage Windows…

Brendan Smith

AmnesiaStealer Hijacks Mac Browser Sessions After ClickFix

AmnesiaStealer spreads through a counterfeit GitHub page, steals Mac passwords and browser…

Brendan Smith

Steam Forum ClickFix Installs XMRig Miner via PowerShell

Fake Steam forum fixes are installing an XMRig miner through PowerShell. Check…

Brendan Smith

UAC-0145 Uses Fake CAPTCHA and Security Apps Against Ukraine

CERT-UA says UAC-0145 is using ClickFix pages, fake security tools, Signal lures,…

Brendan Smith

ACR Stealer ClickFix Attacks: What to Check After Running the Command

Microsoft tracked ACR Stealer ClickFix chains using WebDAV, MSHTA and PowerShell. Check…

Stephanie Adlam

Potemkin Loader Turns ClickFix Into 11-Host Intrusion

A ClickFix command dropped Potemkin Loader, RMMProject and EtherRAT across 11+ hosts.…

Brendan Smith

Trojan:JS/Obfuse.NF!MTB: PowerShell Alert Keeps Coming Back

What Trojan:JS/Obfuse.NF!MTB means when Defender keeps catching hidden PowerShell, and how to…

Brendan Smith

Ghost CMS Exploit Poisons 700 Sites for ClickFix Malware

Attackers are exploiting Ghost CMS CVE-2026-26980 to inject ClickFix loaders into trusted…

Stephanie Adlam

AI Assistant

Hello! 👋 How can I help you today?