← BACK TO FEED
TAG

clickfix3 articles

ACR Stealer Is Raiding Enterprise Networks and All It Needs Is for Someone to Press Enter

ACR Stealer, an infostealer active since 2024, is being distributed through ClickFix lures that trick users into pasting malicious commands into Windows' Run dialog, requiring no vulnerability or exploit to succeed. Once executed, the malware uses two delivery chains — one file-based and one nearly entirely in-memory — to steal browser passwords, session tokens, and Microsoft 365 documents, with techniques including payload concealment inside JPEG pixels and blockchain-based command-and-control infrastructure. Defenders are advised to block the paste-and-run vector via Group Policy, apply application control rules, revoke (not just rotate) compromised tokens, and hunt for indicators such as rundll32.exe making unexplained network connections or scheduled tasks disguised as software updates.

19 Jul 2026

FBI Director's Merch Site Is Serving Malware to macOS Users

FBI Director Kash Patel's merchandise website, BasedApparel.com, was found hosting a "ClickFix" malware attack that tricks macOS users into running a malicious command by disguising it as a Cloudflare human-verification process. Victims are prompted to copy what appears to be a simple verification code, but the clipboard actually receives a hidden obfuscated command that, when run in Terminal, executes a script designed to steal browser credentials and cryptocurrency wallet data. The attack likely resulted from hackers compromising the site, and the malicious payload was flagged by 27 antivirus engines as a Trojan/infostealer.

22 May 2026

Reaper Malware Hits macOS: Steals Passwords, Drains Crypto Wallets, Then Quietly Moves In

A new macOS malware variant called Reaper, an updated version of the SHub stealer, targets users by spoofing trusted domains like Apple, Microsoft, and Google to steal passwords, cryptocurrency wallet credentials, and sensitive files. Unlike earlier versions, it bypasses Apple's Terminal entirely by using macOS Script Editor to execute its malicious payload, circumventing defences added in macOS Tahoe 26.4. The malware also establishes persistent backdoor access by disguising itself as a Google Software Update process, allowing attackers to remotely execute code on compromised machines every 60 seconds.

20 May 2026