Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-06 · 02:16 UTC
articleTotal: 1194 reports

Filtered Reports

18 / 18 results
Active filter:tag: #clickfix✕ clear
5,400+ compromised sites deliver ClickFix via BNB Smart Chain contractshighbug_reportVulnerability
bug_reportVulnerability

5,400+ compromised sites deliver ClickFix via BNB Smart Chain contracts

Over 5,400 compromised small-business websites used as distribution infrastructure. Targets are end users visiting these sites. ClickFix social engineering payloads hosted on BNB Smart Chain (BSC) blockchain smart contracts.

BleepingComputer5 Sep · 12:29 UTC
ClickFix Operators Dominate Initial Access via Social Engineeringhighperson_alertThreat Actor
person_alertThreat Actor

ClickFix Operators Dominate Initial Access via Social Engineering

ClickFix operators are threat actors leveraging a social engineering technique that manipulates users into executing malicious commands through clipboard manipulation.

Microsoft1 Sep · 09:30 UTC
TerminalFix campaign uses fake CAPTCHAs to deploy reverse tunnelshighbug_reportVulnerability
bug_reportVulnerability

TerminalFix campaign uses fake CAPTCHAs to deploy reverse tunnels

Windows systems with PowerShell and Windows Terminal enabled. Targets organizations with Active Directory environments. Attack vector: compromised websites displaying fake Cloudflare CAPTCHA prompts.

Microsoft31 Aug · 16:51 UTC
19 malicious Chrome/Edge extensions steal crypto and credentialshighbug_reportVulnerability
bug_reportVulnerability

19 malicious Chrome/Edge extensions steal crypto and credentials

Google Chrome and Microsoft Edge users who installed any of 19 malicious extensions, including "Enable Right Click & Copy" (70,000+ Chrome users, 10,000+ Edge users). Campaign active since early 2024.

Google30 Aug · 12:17 UTC
TerminalFix campaign uses fake CAPTCHAs to deploy reverse-tunnel backdoorhighbug_reportVulnerability
bug_reportVulnerability

TerminalFix campaign uses fake CAPTCHAs to deploy reverse-tunnel backdoor

Organizations across multiple sectors using Windows environments with PowerShell and Windows Terminal. Attack leverages compromised websites serving fake Cloudflare CAPTCHA pages to social engineer users into executing malicious PowerShell commands.

Microsoft30 Aug · 05:36 UTC
24 npm packages abuse unpkg mirrors as phishing infrastructurehighbug_reportVulnerability
bug_reportVulnerability

24 npm packages abuse unpkg mirrors as phishing infrastructure

24 malicious npm packages (e.g., bgzxcuite2, prezdentkxheiw, egair0810) hosted on npm registry and mirrored on unpkg.com and similar CDN services. Affects users who click links to these mirrored HTML pages, not developers installing packages directly…

npm25 Aug · 09:52 UTC
WordlistLoader and SynkLoader malware target Windows via ClickFix and Teamshighbug_reportVulnerability
bug_reportVulnerability

WordlistLoader and SynkLoader malware target Windows via ClickFix and Teams

Windows endpoints exposed to ClearFake/ClickFix campaigns (WordlistLoader delivering Amatera Stealer) and Microsoft Teams phishing (SynkLoader credential theft).

Microsoft24 Aug · 10:35 UTC
ClickFix attacks deliver macOS stealer targeting crypto wallets and Keychainhighbug_reportVulnerability
bug_reportVulnerability

ClickFix attacks deliver macOS stealer targeting crypto wallets and Keychain

macOS systems (all CPU architectures). Users tricked into pasting malicious commands into Terminal. Targets cryptocurrency wallets (Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, XRP), browser passwords, Apple iCloud Keychain, and cached credentials.

Apple7 Aug · 16:29 UTC
ClickFix campaign delivers Go-based macOS stealer targeting crypto walletshighbug_reportVulnerability
bug_reportVulnerability

ClickFix campaign delivers Go-based macOS stealer targeting crypto wallets

macOS users across all versions; targets cryptocurrency wallets (Bitcoin, Ethereum, Litecoin, Dogecoin, Monero, XRP), browser password databases, Apple Keychain, and cached browser credentials.

BleepingComputer6 Aug · 20:37 UTC
ClickFix Campaign Uses Browser Fingerprinting to Target macOS Usershighperson_alertThreat Actor
person_alertThreat Actor

ClickFix Campaign Uses Browser Fingerprinting to Target macOS Users

ClickFix is a macOS-focused social engineering campaign tracked by Microsoft Threat Intelligence. The operators remain unidentified, but the campaign demonstrates sophisticated evasion capabilities through server-side browser fingerprinting across mo…

Apple5 Aug · 16:44 UTC
macOS ClickFix campaign adds fingerprinting to evade detectionhighbug_reportVulnerability
bug_reportVulnerability

macOS ClickFix campaign adds fingerprinting to evade detection

macOS users targeted via 250+ algorithmically generated domains (e.g., filecopperbasket, apricotfilepoint[.]com). Campaign delivers MacSync and Atomic Stealer (AMOS) infostealers. All macOS versions susceptible to social engineering technique.

Apple5 Aug · 13:48 UTC
DOUBLECUP LaaS Uses ClickFix and Steganography to Deploy CountLoaderhighperson_alertThreat Actor
person_alertThreat Actor

DOUBLECUP LaaS Uses ClickFix and Steganography to Deploy CountLoader

DOUBLECUP is a Russian loader-as-a-service (LaaS) operation active since early June 2026. The service provides operators with licenses and a Go-based Windows GUI client to orchestrate campaigns that deliver malware via ClickFix social engineering lur…

The Hacker News4 Aug · 07:03 UTC
DOUBLECUP loader-as-a-service delivers malware via ClickFix attackshighperson_alertThreat Actor
person_alertThreat Actor

DOUBLECUP loader-as-a-service delivers malware via ClickFix attacks

DOUBLECUP is a Russian loader-as-a-service platform that has operated since early June 2026. The service provides customers with licenses and a Go-based Windows tool for creating malicious ClickFix campaigns.

Microsoft3 Aug · 18:01 UTC
ClickFix Abuses Steam Forums to Deliver XMRig Cryptominerhighperson_alertThreat Actor
person_alertThreat Actor

ClickFix Abuses Steam Forums to Deliver XMRig Cryptominer

ClickFix is a threat actor conducting social engineering campaigns that leverage fake technical support content to distribute malware. The actor exploits user trust in community-driven platforms, specifically targeting gaming communities through Stea…

Steam25 Jul · 20:37 UTC
UAC-0145 (Sandworm sub-cluster) deploys ClickFix lures vs Ukrainehighperson_alertThreat Actor
person_alertThreat Actor

UAC-0145 (Sandworm sub-cluster) deploys ClickFix lures vs Ukraine

UAC-0145 is a sub-cluster of Sandworm, a Russian state-sponsored APT group attributed to the GRU (Main Intelligence Directorate of the General Staff of the Armed Forces of the Russian Federation).

The Hacker News19 Jul · 11:30 UTC
ClickFix Targets macOS with Terminal-Based Infostealer Campaignhighperson_alertThreat Actor
person_alertThreat Actor

ClickFix Targets macOS with Terminal-Based Infostealer Campaign

ClickFix is a threat actor conducting social engineering campaigns that trick users into executing malicious commands. The actor leverages deceptive techniques to convince victims to manually run Terminal commands on macOS systems, facilitating the d…

Apple23 Jun · 16:30 UTC
DriveSurge Distributes Malware via ClickFix and FakeUpdate Campaignshighperson_alertThreat Actor
person_alertThreat Actor

DriveSurge Distributes Malware via ClickFix and FakeUpdate Campaigns

DriveSurge is a threat actor conducting large-scale malware distribution operations. The actor leverages compromised website infrastructure at scale, utilizing thousands of sites to host and deliver malicious payloads.

BleepingComputer1 Jun · 20:14 UTC
Ghost CMS SQL injection (CVE-2026-26980) exploited in ClickFix campaigncriticalbug_reportVulnerability
bug_reportVulnerability

Ghost CMS SQL injection (CVE-2026-26980) exploited in ClickFix campaign

Ghost CMS Content API, all versions prior to patch. Over 700 sites confirmed compromised. Unauthenticated attackers can exploit the SQL injection vulnerability remotely.

CVE-2026-2698025 May · 10:02 UTC