Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
18 / 18 results
highbug_reportVulnerability5,400+ compromised sites deliver ClickFix via BNB Smart Chain contracts
Over 5,400 compromised small-business websites used as distribution infrastructure. Targets are end users visiting these sites. ClickFix social engineering payloads hosted on BNB Smart Chain (BSC) blockchain smart contracts.
highperson_alertThreat ActorClickFix Operators Dominate Initial Access via Social Engineering
ClickFix operators are threat actors leveraging a social engineering technique that manipulates users into executing malicious commands through clipboard manipulation.
highbug_reportVulnerabilityTerminalFix campaign uses fake CAPTCHAs to deploy reverse tunnels
Windows systems with PowerShell and Windows Terminal enabled. Targets organizations with Active Directory environments. Attack vector: compromised websites displaying fake Cloudflare CAPTCHA prompts.
highbug_reportVulnerability19 malicious Chrome/Edge extensions steal crypto and credentials
Google Chrome and Microsoft Edge users who installed any of 19 malicious extensions, including "Enable Right Click & Copy" (70,000+ Chrome users, 10,000+ Edge users). Campaign active since early 2024.
highbug_reportVulnerabilityTerminalFix campaign uses fake CAPTCHAs to deploy reverse-tunnel backdoor
Organizations across multiple sectors using Windows environments with PowerShell and Windows Terminal. Attack leverages compromised websites serving fake Cloudflare CAPTCHA pages to social engineer users into executing malicious PowerShell commands.
highbug_reportVulnerability24 npm packages abuse unpkg mirrors as phishing infrastructure
24 malicious npm packages (e.g., bgzxcuite2, prezdentkxheiw, egair0810) hosted on npm registry and mirrored on unpkg.com and similar CDN services. Affects users who click links to these mirrored HTML pages, not developers installing packages directly…
highbug_reportVulnerabilityWordlistLoader and SynkLoader malware target Windows via ClickFix and Teams
Windows endpoints exposed to ClearFake/ClickFix campaigns (WordlistLoader delivering Amatera Stealer) and Microsoft Teams phishing (SynkLoader credential theft).
highbug_reportVulnerabilityClickFix attacks deliver macOS stealer targeting crypto wallets and Keychain
macOS systems (all CPU architectures). Users tricked into pasting malicious commands into Terminal. Targets cryptocurrency wallets (Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, XRP), browser passwords, Apple iCloud Keychain, and cached credentials.
highbug_reportVulnerabilityClickFix campaign delivers Go-based macOS stealer targeting crypto wallets
macOS users across all versions; targets cryptocurrency wallets (Bitcoin, Ethereum, Litecoin, Dogecoin, Monero, XRP), browser password databases, Apple Keychain, and cached browser credentials.
highperson_alertThreat ActorClickFix Campaign Uses Browser Fingerprinting to Target macOS Users
ClickFix is a macOS-focused social engineering campaign tracked by Microsoft Threat Intelligence. The operators remain unidentified, but the campaign demonstrates sophisticated evasion capabilities through server-side browser fingerprinting across mo…
highbug_reportVulnerabilitymacOS ClickFix campaign adds fingerprinting to evade detection
macOS users targeted via 250+ algorithmically generated domains (e.g., filecopperbasket, apricotfilepoint[.]com). Campaign delivers MacSync and Atomic Stealer (AMOS) infostealers. All macOS versions susceptible to social engineering technique.
highperson_alertThreat ActorDOUBLECUP LaaS Uses ClickFix and Steganography to Deploy CountLoader
DOUBLECUP is a Russian loader-as-a-service (LaaS) operation active since early June 2026. The service provides operators with licenses and a Go-based Windows GUI client to orchestrate campaigns that deliver malware via ClickFix social engineering lur…
highperson_alertThreat ActorDOUBLECUP loader-as-a-service delivers malware via ClickFix attacks
DOUBLECUP is a Russian loader-as-a-service platform that has operated since early June 2026. The service provides customers with licenses and a Go-based Windows tool for creating malicious ClickFix campaigns.
highperson_alertThreat ActorClickFix Abuses Steam Forums to Deliver XMRig Cryptominer
ClickFix is a threat actor conducting social engineering campaigns that leverage fake technical support content to distribute malware. The actor exploits user trust in community-driven platforms, specifically targeting gaming communities through Stea…
highperson_alertThreat ActorUAC-0145 (Sandworm sub-cluster) deploys ClickFix lures vs Ukraine
UAC-0145 is a sub-cluster of Sandworm, a Russian state-sponsored APT group attributed to the GRU (Main Intelligence Directorate of the General Staff of the Armed Forces of the Russian Federation).
highperson_alertThreat ActorClickFix Targets macOS with Terminal-Based Infostealer Campaign
ClickFix is a threat actor conducting social engineering campaigns that trick users into executing malicious commands. The actor leverages deceptive techniques to convince victims to manually run Terminal commands on macOS systems, facilitating the d…
highperson_alertThreat ActorDriveSurge Distributes Malware via ClickFix and FakeUpdate Campaigns
DriveSurge is a threat actor conducting large-scale malware distribution operations. The actor leverages compromised website infrastructure at scale, utilizing thousands of sites to host and deliver malicious payloads.
criticalbug_reportVulnerabilityGhost CMS SQL injection (CVE-2026-26980) exploited in ClickFix campaign
Ghost CMS Content API, all versions prior to patch. Over 700 sites confirmed compromised. Unauthenticated attackers can exploit the SQL injection vulnerability remotely.