clickfix10 articles
TerminalFix: The ClickFix Variant That Hands Attackers Your Entire Network
is a new variant of ClickFix malware that tricks users into running malicious PowerShell commands via fake Cloudflare CAPTCHA pages on compromised websites. The attack uses a multi-stage process involving DLL sideloading, steganographic payload extraction, and Active Directory reconnaissance, ultimately deploying a Python-based reverse-tunnel backdoor that grants attackers persistent access to the victim's internal network. Microsoft warns the technique is particularly dangerous as it can be exploited to escalate privileges, steal data, and deploy ransomware, and recommends restricting PowerShell execution, monitoring for DLL sideloading, and training employees to recognise ClickFix-style attacks.
Fake OpenAI Codex Ads Are Serving Mac Malware Via Terminal Commands
Cybercriminals are running a malware campaign targeting Mac developers by placing fake sponsored Google ads for OpenAI Codex, directing victims to convincing but fraudulent download pages. Instead of providing an installer, the sites instruct users to run a terminal command that covertly triggers a multi-stage malware infection — a tactic known as "ClickFix" — ultimately deploying what appears to be the AMOS infostealer. A similar fake page impersonating Anthropic's Claude Code was also discovered sharing the same infrastructure, suggesting a broader campaign against developers seeking AI coding tools.
Nearly 2,000 Hacked WordPress Sites Are Powering a Surprisingly Sophisticated Criminal Operation
A large-scale cybercrime operation called **StopAndProtect** has compromised nearly 2,000 outdated WordPress websites, using them as infrastructure to distribute malware, issue attacker commands, and store stolen data from victims. The campaign begins with fake ClickFix CAPTCHA prompts that trick users into running malicious PowerShell commands, deploying a toolkit that includes ransomware, a credential stealer, a screen locker, a worm, and a chat utility for communicating with victims. As of late July 2026, over 6,000 unique IP addresses have been compromised, with researchers urging users to be wary of unexpected CAPTCHA prompts that instruct them to run commands outside the browser.
AmnesiaStealer: The macOS Malware That Watches You Browse in Real Time
is a newly discovered Rust-based macOS malware distributed via a fake GitHub page using ClickFix-style social engineering, tricking victims into running a malicious Terminal command. Once installed, it harvests sensitive data including browser databases, keychains, Apple Notes, and documents, while also attempting to bypass macOS's TCC framework to gain broader access. A particularly notable feature is its remote-control "stream module," which uses the Chrome DevTools Protocol to launch a hidden browser session, giving attackers live, interactive control over the victim's browsing activity.
ClickFix Malware Can Slowly Bleed Your Crypto Wallet Dry
ClickFix-style attacks are being used to deliver a Go-based macOS malware that steals browser passwords, Apple Keychain data, and cryptocurrency wallet contents, with the ability to gradually drain funds across multiple cryptocurrencies including Bitcoin, Ethereum, and Monero. The attack tricks victims into pasting a command into Terminal, which profiles the system, downloads a compatible payload, and uses a fake error prompt to harvest system credentials. The malicious infrastructure is linked to Aeza Group, a Russian bulletproof hosting provider sanctioned by the US, UK, and Australia.
North Korea's Contagious Interview Campaign Goes Full ClickFix With Blockchain C2
North Korea-linked threat actors have launched a sophisticated macOS malvertising campaign, dubbed a new iteration of "Contagious Interview," that redirects users to fake websites displaying a convincing full-screen fake software update to trick them into running malicious Terminal commands via the ClickFix technique. The malware uses "EtherHiding" — embedding C2 server addresses in Ethereum smart contracts — to resist takedowns, ultimately delivering an information stealer targeting 157 cryptocurrency wallets and a malicious Chrome extension designed to drain victims' funds. Notably, this campaign departs from the group's typical fake job interview lures, instead targeting ordinary web searches, suggesting North Korean operators are broadening their attack vectors beyond developer recruitment scenarios.
TELEPUZ: The Modular Malware Using Telegram, Steam, and a Blockchain to Phone Home
TELEPUZ is a newly discovered modular malware written in C that has been spreading since late April 2026 through ClickFix-style social engineering attacks, which trick users into pasting and executing malicious commands. Once installed, it employs extensive evasion techniques — including anti-VM checks, AMSI/ETW disabling, and obfuscation — before establishing contact with its command-and-control server via WebSockets to steal data, log keystrokes, capture screenshots, and execute commands. The malware uses multiple fallback methods to locate its C2 server, including Telegram, Steam, DNS queries, and a Polygon blockchain smart contract, and is believed to be an early-stage malware-as-a-service (MaaS) offering based on its high build volume and rapid development pace.
ACR Stealer Is Raiding Enterprise Networks and All It Needs Is for Someone to Press Enter
ACR Stealer, an infostealer active since 2024, is being distributed through ClickFix lures that trick users into pasting malicious commands into Windows' Run dialog, requiring no vulnerability or exploit to succeed. Once executed, the malware uses two delivery chains — one file-based and one nearly entirely in-memory — to steal browser passwords, session tokens, and Microsoft 365 documents, with techniques including payload concealment inside JPEG pixels and blockchain-based command-and-control infrastructure. Defenders are advised to block the paste-and-run vector via Group Policy, apply application control rules, revoke (not just rotate) compromised tokens, and hunt for indicators such as rundll32.exe making unexplained network connections or scheduled tasks disguised as software updates.
FBI Director's Merch Site Is Serving Malware to macOS Users
FBI Director Kash Patel's merchandise website, BasedApparel.com, was found hosting a "ClickFix" malware attack that tricks macOS users into running a malicious command by disguising it as a Cloudflare human-verification process. Victims are prompted to copy what appears to be a simple verification code, but the clipboard actually receives a hidden obfuscated command that, when run in Terminal, executes a script designed to steal browser credentials and cryptocurrency wallet data. The attack likely resulted from hackers compromising the site, and the malicious payload was flagged by 27 antivirus engines as a Trojan/infostealer.
Reaper Malware Hits macOS: Steals Passwords, Drains Crypto Wallets, Then Quietly Moves In
A new macOS malware variant called Reaper, an updated version of the SHub stealer, targets users by spoofing trusted domains like Apple, Microsoft, and Google to steal passwords, cryptocurrency wallet credentials, and sensitive files. Unlike earlier versions, it bypasses Apple's Terminal entirely by using macOS Script Editor to execute its malicious payload, circumventing defences added in macOS Tahoe 26.4. The malware also establishes persistent backdoor access by disguising itself as a Google Software Update process, allowing attackers to remotely execute code on compromised machines every 60 seconds.