Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: clickfix (20 articles)Clear

Lunex stealer abuses vulnerable AMD driver to disable security tools and steal credentials

Ontinue tied the Psychedelic Stealer, spread through compromised Ukrainian websites using ClickFix-style fake Cloudflare verification pages, to a wider malware-as-a-service platform called Lunex. The chain starts with a bogus CAPTCHA that delivers a malicious MSI, which drops LunexLoader. The loader bypasses User Account Control through the CMSTPLUA COM object, then uses a bring-your-own-vulnerable-driver technique against the AMD Radeon Software driver PDFWKRNL.sys, affected by CVE-2023-20598, to escalate and evade defenses before fetching the stealer. Researchers note BYOVD is rarely used as a precursor to an infostealer. The final payload extracts credentials from seven Chromium-based browsers, exfiltrates cryptocurrency wallets, and installs a PowerShell-based browser Native Messaging Host for persistent remote filesystem access.

Check
Block the vulnerable PDFWKRNL.sys driver via Microsoft's blocklist, alert on ClickFix-style CAPTCHA lures, and hunt for rogue browser Native Messaging Hosts.
Affected
Windows users tricked by fake Cloudflare CAPTCHA lures run an MSI that loads a vulnerable AMD driver to disable defenses and steal browser and wallet data.
Fix
Enable the vulnerable driver blocklist, restrict MSI and script execution, block copy-paste run-dialog lures, and monitor for UAC bypass via CMSTPLUA.

New ChainScript trojan hides command server in a Polygon blockchain smart contract

Blackpoint researchers documented ChainScript, a previously unseen remote access trojan spread through ClickFix-style lures that impersonate Spotify, Zoom, and Microsoft Teams. It uses an EtherHiding-style technique, querying a Polygon smart contract to locate its active WebSocket command infrastructure so operators can rotate servers without changing the malware. The chain starts with a ClickFix lure leading to a malicious MSI run through msiexec, which deploys a Node.js runtime and launches a JavaScript agent through hidden PowerShell and VBScript stages dropped into Microsoft-looking paths under LOCALAPPDATA. ChainScript offers interactive command shells, file operations, screenshots, remote JavaScript, and enumeration of cryptocurrency wallets in both desktop applications and browser extensions.

Check
Block ClickFix-style paste-to-run lures, alert on msiexec spawning Node.js with PowerShell and VBScript stages, and review crypto wallet exposure on developer endpoints.
Affected
Users tricked by fake Spotify, Zoom, or Teams ClickFix lures run an MSI that installs a resilient RAT enumerating desktop and browser crypto wallets.
Fix
Restrict msiexec and script interpreters, monitor outbound blockchain RPC from endpoints, and educate staff against copy-paste terminal or run-dialog instructions.

Stolen Cloudflare key let attackers poison Brevo scripts on 100,000 sites

Attackers stole a Cloudflare API key from marketing platform Brevo and used it to inject malicious code into the scripts that Brevo's customers embed on their own websites, affecting more than 100,000 sites. The key was long-lived, had full account permissions, and was hardcoded in application source code, which let the attackers create a Cloudflare Worker that modified Brevo's forms, widget, and loader scripts at the network edge for about five and a half hours. Visitors saw a fake verification page with ClickFix instructions to run a command on Windows, and on WordPress sites where an admin was logged in, the script tried to silently install a backdoor plugin.

Check
Keep API keys out of source code, replace long-lived full-permission keys with scoped short-lived credentials in a secrets manager, and review third-party scripts your sites embed for unexpected changes or injected content.
Affected
Websites embedding Brevo's scripts and their visitors during the incident; a stolen key let attackers modify those trusted scripts at the edge to push ClickFix malware and a WordPress backdoor plugin.
Fix
Scope and rotate API keys, store them outside code, constrain embedded third-party scripts with subresource integrity and content security policy, monitor for edge content changes, and teach users to reject paste-a-command prompts.

Attackers abuse the trusted Node.js runtime to run malware past defenses

Symantec reported that threat actors are abusing the legitimate, digitally signed Node.js runtime to run malicious JavaScript while slipping past security tools, in attacks on government, technology, and hospitality targets since February. Because the Node.js executable is a trusted developer tool, defenses rarely flag it, so instead of dropping a malicious program the attackers stage the genuine runtime and keep their harmful logic in interpreted scripts. They gain persistence through a Windows registry startup key and, in one case, pulled command-and-control instructions from the blockchain using a technique called EtherHiding. The activity has been tied to a ClickFix social-engineering entry point and an initial-access broker.

Check
Hunt for unexpected Node.js installations on machines that should not run developer tools, suspicious registry startup entries invoking the runtime, and outbound traffic to blockchain endpoints used for command and control.
Affected
Windows environments where a signed Node.js runtime can be introduced and run scripts unnoticed; attackers use it to execute malicious JavaScript, persist through registry keys, and evade tools that trust the binary.
Fix
Apply application control to restrict where the Node.js runtime may run, alert on its use outside development, monitor script execution and registry run-key changes, and block known blockchain command-and-control and ClickFix infrastructure.

ClickFix campaign hides its command server on the Polygon blockchain

Researchers at GuidePoint found a ClickFix campaign that compromised at least 31 organizations' websites and abuses the Polygon blockchain to run its command-and-control, a technique called EtherHiding. Visitors arriving from search engines hit a fake human-verification prompt that abuses Cloudflare's overlay and tells them to paste a command, which installs a persistent backdoor. Instead of a fixed server address that defenders can block, the backdoor fetches its current instructions from a Polygon smart contract every minute, giving the attacker a censorship-resistant, easily updated address book. This breaks the usual defense of blocking a hardcoded command server, so defenders should focus on behavior and audit their public-facing sites.

Check
Teach users that no verification prompt should ask them to paste commands, audit public-facing websites for injected scripts, and hunt for backdoors that resolve command servers through blockchain queries.
Affected
Organizations whose websites are compromised to serve the fake verification lure, and users tricked into running the pasted command; the resulting backdoor persists and pulls updatable instructions from the blockchain.
Fix
Detect on behavior rather than static addresses, block or flag outbound blockchain-resolution queries from endpoints, monitor for domain-generation patterns, continuously audit websites for injected code, and train users against paste-a-command verification tricks.

TerminalFix tricks users with fake CAPTCHAs into pasting a backdoor command

A social-engineering campaign dubbed TerminalFix uses fake Cloudflare CAPTCHA pages, often served from compromised websites, to trick visitors into copying and running a malicious PowerShell command in their terminal. It is a refined take on the ClickFix technique, tuned to make complex scripts run more reliably, and it deploys a reverse-tunnel backdoor through a multi-stage chain involving DLL sideloading, hiding payloads inside images, and an outbound WebSocket connection for command and control. The campaign has hit organizations across several sectors. The core deception is simple to teach against: a legitimate CAPTCHA never asks you to paste and run commands in a terminal or Run dialog.

Check
Warn users that no real CAPTCHA ever asks them to paste commands into a terminal, and treat any such prompt as an attack, closing the page and reporting it.
Affected
Users lured to compromised or malicious sites showing fake CAPTCHA verification; following the prompt to run a PowerShell command installs a reverse-tunnel backdoor that gives attackers remote access to the device.
Fix
Enforce application control and PowerShell script-block logging, monitor for anomalous outbound WebSocket traffic and DLL sideloading, restrict who can run scripts, and train users to recognize fake CAPTCHA and ClickFix lures.

Attackers abuse npm and its mirrors to host fake CAPTCHA phishing pages

Researchers at OX Security found a campaign using two dozen npm packages as free phishing infrastructure rather than as malware aimed at developers. Each package is just a single HTML page, harmless to install, but once served through npm content-delivery mirrors like unpkg it becomes a live, fully rendered fake Cloudflare CAPTCHA page hosted on a trusted domain. The page then redirects victims to ClickFix-style phishing infrastructure, and while it currently forwards to a legitimate site, it can be reconfigured to deliver any phishing payload. The trick is not infecting people who install the packages, but abusing the registry and its mirrors as validated, reputable storage for attacker content.

Check
Treat fake CAPTCHA and ClickFix pages as hostile even when served from trusted domains like unpkg, and educate users not to run commands or steps a CAPTCHA prompt tells them to perform.
Affected
Anyone lured to a fake CAPTCHA page hosted on a trusted npm mirror; the pages redirect to ClickFix phishing, exploiting the reputation of legitimate infrastructure to bypass suspicion and some blocking.
Fix
Monitor and filter for HTML content served from package-mirror domains, block known phishing and ClickFix infrastructure, apply reputation-aware web filtering rather than trusting domains outright, and train users on fake CAPTCHA lures.

AmnesiaStealer hijacks live macOS browser sessions to ride past logins

Jamf detailed a new macOS information stealer, AmnesiaStealer, spread through ClickFix lures that trick users into running a command from a fake download page. Beyond harvesting the login password, keychain, browser data, and cryptocurrency wallets, it includes a module that clones the victim's Chromium browser profile, including its logged-in state, into a hidden browser on the infected Mac and gives the attacker live remote control of it through the browser's debugging protocol. Because the session runs on the victim's own device with their real identifiers, this lets the attacker use authenticated accounts while sidestepping multi-factor authentication. Jamf calls it the first macOS malware to combine profile cloning with live remote browser control.

Check
Warn Mac users never to paste and run commands from a web page or fake download prompt, and treat unexpected browser sessions or new hidden browser processes as a compromise indicator.
Affected
macOS users tricked by ClickFix lures into running the loader; AmnesiaStealer steals credentials and wallets and clones logged-in browser sessions for live remote use, letting attackers bypass multi-factor authentication.
Fix
Block known ClickFix infrastructure, educate users against pasted-command prompts, keep macOS and security tooling current, and monitor for browsers launched in debugging mode and unexpected headless browser activity.

macOS ClickFix campaign fingerprints visitors to hide its malware from analysts

Microsoft Threat Intelligence detailed a macOS ClickFix operation spanning more than 250 domains that now fingerprints visitors before deciding whether to show a malware lure. The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software download, an anti-analysis layer rather than a change to the attack itself. The lure still requires the victim to copy and run an obfuscated command in Terminal, which fetches scripts and installs an infostealer, in this case Atomic Stealer, that targets credentials, browser data, authentication stores, and cryptocurrency wallets. Many domains follow a dictionary-word naming pattern using the word file.

Check
Warn Mac users never to paste and run Terminal commands from a web verification or fix prompt, and use the file-plus-dictionary-word domain pattern as a threat-hunting pivot.
Affected
macOS users who follow fake software-fix prompts; the fingerprinting gate hides the lure from analysis while serving selected victims an infostealer that harvests credentials, browser data, and crypto wallets.
Fix
Update to macOS 26.4 for its new Terminal and XProtect protections, block known campaign domains, monitor endpoints for scripts run from Terminal, and reinforce that legitimate fixes never require pasted commands.

ClickLock macOS malware kills apps in a loop until victims type their password

Group-IB detailed ClickLock, a macOS infostealer that coerces victims into handing over their login password. It arrives when a user is tricked into pasting a command into Terminal from a fake verification page, then shows a fake system dialog asking for the password. If the victim refuses, ClickLock begins killing core apps like Finder, the Dock, and browsers every 210 milliseconds, leaving only a password box on an unusable desktop, while also suppressing security notifications. Once the password is entered, it steals the Keychain, browser credentials, and cryptocurrency wallets and sends them to a Telegram bot. Group-IB counted at least 100 targets across 33 countries, over half in Europe.

Check
Warn Mac users never to paste Terminal commands from a website, and never enter a password to stop apps crashing; a Mac killing its own apps behind a password box is malware.
Affected
Mac users tricked into pasting a command from a fake verification page; ClickLock pressures them into entering their password by killing apps in a loop, then steals Keychain data and crypto wallets.
Fix
Only run Terminal commands you fully understand from trusted sources, treat app-killing loops and unexpected password prompts as attacks, and if infected, change passwords and wallet keys from a clean device.