threat-intel TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor Microsoft has disclosed a new ClickFix variant, TerminalFix, that uses fake Cloudflare CAPTCHAs to trick users into executing malicious PowerShell commands via Windows Terminal or PowerShell. The campaign employs a multi-stage attack leveraging DLL sideloading, reconnaissance, and a reverse-tunnel backdoor to gain pers… The Hacker News · 13h ago High clickfixdll sideloadingreverse tunnel
threat-intel E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands Threat actors are utilizing FTP banner responses as dead drop resolvers to deliver two new remote access trojans, E4del and PINHOLE RAT. E4del, a Node.js-based RAT, employs a dynamic beaconing system to blend in with net… The Hacker News · 5d ago High UNdvrftpremote access trojan
threat-intel Foul Language: WordlistLoader Disguises Malware as Ordinary Text A new malware loader called WordlistLoader is being used to deliver the Amatera infostealer, primarily through ClickFix-style campaigns. WordlistLoader disguises malicious code using lists of ordinary English words, allo… Dark Reading · 6d ago High malwareloaderinfostealer
threat-intel WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords Two new malware families, WordlistLoader and SynkLoader, are being used to deliver the Amatera Stealer via ClickFix phishing campaigns. WordlistLoader reconstructs shellcode for Amatera, utilizing techniques to evade det… The Hacker News · 6d ago High phishingransomwaremalware
threat-intel ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More This week saw a surge in exploitation activity and new malware discoveries. A China-nexus APT is leveraging a newly patched VMware vulnerability to deploy a backdoor and ransomware (Babuk-derived). Simultaneously, a zero… The Hacker News · Aug 17, 2026 High CVE-2026-59310CVE-2026-65400CVE-2026-68820CHNOFRexploitvulnerabilityransomware
threat-intel AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions A new multi-stage Rust-based macOS information stealer, dubbed AmnesiaStealer, is being distributed through a fake GitHub download page as part of ClickFix attacks. The malware steals user data, including passwords and b… SecurityWeek · Aug 14, 2026 High CVE-2020-9771macosrustinformation stealer
threat-intel ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets ClickFix-style attacks are being used to deliver a Go-based macOS stealer that can drain cryptocurrency wallets and steal browser-stored passwords and Apple iCloud Keychain data. The malware, developed by the Aeza Group… The Hacker News · Aug 7, 2026 High USUKAUmacoscryptocurrencystealer
threat-intel Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures A macOS ClickFix operation is using browser fingerprinting to deliver malware lures to a targeted subset of Mac users. The operation, involving over 250 domains and distributing malware like MacSync and AMOS, hides the m… The Hacker News · Aug 5, 2026 High browser fingerprintingmacosclickfix
threat-intel DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT DOUBLECUP, a new Russian LaaS service, is using ClickFix lures to deliver malware, specifically CountLoader (Windows and macOS) and DeviceManager (Windows and macOS). DeviceManager utilizes blockchain-based C2 resolution… The Hacker News · Aug 4, 2026 High RUsteganographyclickfixransomware
threat-intel DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware North Korean-linked threat actors are using a sophisticated macOS malvertising campaign to deliver crypto-stealing malware. The campaign mimics a fake software update sequence to trick users into executing a malicious co… The Hacker News · Jul 30, 2026 High KPmacosmalvertisingcrypto-stealer
threat-intel Golden Chickens Resurfaces With Four New Malware Families and Modular Implants The Golden Chickens malware-as-a-service (MaaS) group, tracked as TAG-195, has resurfaced with four new malware families, indicating continued development and a shift towards a more flexible, modular approach to evade de… The Hacker News · Jul 24, 2026 High malware-as-a-servicemodular malwareclickfix
threat-intel Ukraine warns fake CAPTCHAs are being used to make you hack yourself Ukraine's CERT-UA has warned that Russian hackers, specifically a branch of the Sandworm group, are using fake CAPTCHA challenges to trick users into executing PowerShell commands on their own computers, installing recon… Graham Cluley · Jul 21, 2026 High RUclickfixpowershellcaptcha
threat-intel UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware Russian state-sponsored actors, linked to the Sandworm group and GRU, are using a ClickFix social engineering tactic to deliver malware to Ukrainian devices. They are leveraging fake CAPTCHA checks on compromised website… The Hacker News · Jul 19, 2026 High RUsocial engineeringclickfixrussia
threat-intel New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands A new modular malware, TELEPUZ, is spreading via ClickFix lures and is being developed by a solo developer or small team. The malware steals data, runs commands, and evades detection through various techniques, including… The Hacker News · Jul 16, 2026 High BRINclickfixpastejackingmalware-as-a-service
threat-intel UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign A sophisticated, Russian-speaking threat actor, UAT-11795, has been conducting a financially motivated campaign targeting users in the U.S. and Europe since June 2025. The campaign utilizes a novel combination of tools,… Cisco Talos · Jul 16, 2026 High USGEROclickfixsocial engineeringc2
threat-intel And the Winner in Dominant Malware Delivery? ClickFix ClickFix, a social engineering technique where attackers trick users into executing malicious commands via error messages, has become the dominant method for malware delivery, according to a recent ReliaQuest analysis. T… Dark Reading · Jul 1, 2026 High USsocial engineeringmalware deliveryobfuscation
threat-intel New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns A new stealthy backdoor, Mistic (MLTBackdoor), linked to the KongTuke IAB has been used in financially motivated attacks targeting organizations across insurance, education, IT, and professional services since April 2026… The Hacker News · Jun 25, 2026 High USbackdoorremote access trojanclickfix
threat-intel Stealthy Mistic backdoor linked to ransomware access broker KongTuke A new stealthy backdoor, dubbed Mistic, has been identified as a tool used by the initial access broker KongTuke to facilitate ransomware attacks against organizations in the insurance, education, IT, and professional se… BleepingComputer · Jun 24, 2026 High USbackdoorinitial accessransomware
malware New macOS ClickFix attack silently mounts DMGs to push infostealer A new macOS ClickFix campaign is using Terminal commands to silently deploy the Atomic macOS Stealer (AMOS) infostealer, targeting users through fake CAPTCHA pages. The malware steals sensitive data like browser credenti… BleepingComputer · Jun 23, 2026 High USmacosclickfixinfostealer
threat-intel ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories This week’s ThreatDay Bulletin highlights several concerning security incidents, including browser extension abuse, macOS malware attacks, AI-powered malware delivery, and a global phishing campaign targeting travel book… The Hacker News · Jun 18, 2026 High CVE-2026-20127CVE-2026-49975USCNJPbrowser extensionsmacos malwareai abuse