https://thehackernews.com/2025/12/storm-0249-escalates-ransomware-attacks.html
Storm-0249 Escalates Ransomware Attacks with ClickFix, Fileless PowerShell, and DLL Sideloading
Storm-0249 now employs ClickFix, fileless PowerShell, and DLL sideloading to gain stealthy access that enables ransomware operations.
ransomware attacks
https://thehackernews.com/2026/01/crashfix-chrome-extension-delivers.html?version=meter+at+null
CrashFix Chrome Extension Delivers ModeloRAT Using ClickFix-Style Browser Crash Lures
Researchers uncovered a CrashFix campaign where a fake Chrome ad blocker crashes browsers to trick users into installing the ModeloRAT malware.
chrome extensiondelivers
https://www.netskope.com/blog/macos-clickfix-lures-deploy-applescript-stealer-persistent-rat
macOS ClickFix Lures Deploy AppleScript Stealer & Persistent RAT - Netskope
Jun 19, 2026 - In April 2026, Netskope Threat Labs reported a ClickFix campaign delivering an AppleScript-based infostealer to macOS users, pilfering sensitive data
macosclickfixluresdeployapplescript
https://thehackernews.com/2025/10/analysing-clickfix-3-reasons-why.html?ref=blog.netmanageit.com
Analysing ClickFix: 3 Reasons Why Copy/Paste Attacks Are Driving Security Breaches
ClickFix attacks use fake CAPTCHAs and clipboard scripts to bypass detection and compromise endpoints.
reasons whycopy paste
https://demo.clickfix.io/
Join ClickFix.io
joinclickfixio
https://www.eset.com/us/about/newsroom/research/eset-threat-report-clickfix-fake-error-surges-spreads-ransomware-and-other-malware/
ESET Threat Report: ClickFix fake error surges, spreads ransomware and other malware | | ESET
ESET has released its latest Threat Report, which summarizes threat landscape trends from December 2024 through May 2025.
eset threat report
https://www.malwarebytes.com/it/blog/threat-intel/2026/03/infiniti-stealer-a-new-macos-infostealer-using-clickfix-and-python-nuitka
Infiniti Stealer: un nuovo infostealer per macOS che utilizza ClickFix e Python/Nuitka |...
Mar 26, 2026 - Un nuovo programma di furto di informazioni per macOS, NukeChain (ora denominato Infiniti Stealer), utilizza pagine CAPTCHA fasulle per indurre gli utenti a...
https://www.techradar.com/pro/security/state-sponsored-actors-spotted-using-clickfix-hacking-tool-developed-by-criminals
State-sponsored actors spotted using ClickFix hacking tool developed by criminals | TechRadar
Apr 18, 2025 - Iranians, Russians, and North Koreans all using ClickFix
https://thehackernews.com/2025/03/microsoft-warns-of-clickfix-phishing.html
Microsoft Warns of ClickFix Phishing Campaign Targeting Hospitality Sector via Fake Booking[.]com...
Microsoft warns of a phishing campaign using ClickFix to spread malware via fake Booking.com emails. Attackers exploit fake CAPTCHA pages to steal cre
https://www.malwarebytes.com/it/blog/news/2026/04/clickfix-finds-new-way-to-infect-macs
ClickFix trova un nuovo modo per infettare i Mac | Malwarebytes
Apr 10, 2026 - Le campagne di ClickFix hanno trovato un modo per aggirare gli avvisi di macOS Tahoe relativi all'incollaggio di comandi nel Terminale. Utilizzano invece...
i macclickfixtrovaunnuovo
https://www.okta.com/blog/threat-intelligence/how-this-click-fix-campaign-leads-to-redline-stealer/
How this ClickFix campaign leads to Redline Stealer | Okta
Okta Threat Intelligence has observed an evolving cyber threat that leverages deceptive CAPTCHA pages to distribute a range of malicious payloads.
clickfixcampaignleadsredlinestealer
https://clickfix.io/
ClickFix.io
ClickFix is the only toolset that's been built specifically for Ontraport users, by Ontraport users.
clickfixio
https://unit42.paloaltonetworks.com/preventing-clickfix-attack-vector/?pdf=print&lg=en&_wpnonce=19daf64377
Fix the Click: Preventing the ClickFix Attack Vector
Aug 4, 2025 - ClickFix campaigns are on the rise. We highlight three that distributed NetSupport RAT, Latrodectus, and Lumma Stealer malware.
the clickfixpreventingattackvector
https://clickfixsim.carsonww.com/
ClickFix Demo
clickfixdemo
https://me-en.kaspersky.com/blog/tag/clickfix/
Tag: ClickFix | Kaspersky official blog
tagclickfixkasperskyofficialblog
https://thehackernews.com/2025/06/new-atomic-macos-stealer-campaign.html
New Atomic macOS Stealer Campaign Exploits ClickFix to Target Apple Users
A new malware campaign tricks macOS users with fake Spectrum CAPTCHA sites to steal passwords and deliver Atomic Stealer malware.
atomic macos stealernewcampaign
https://unit42.paloaltonetworks.com/lampion-malware-clickfix-lures/?pdf=print&lg=en&_wpnonce=949b5ed951
Lampion Is Back With ClickFix Lures
May 6, 2025 - Lampion malware distributors are now using the social engineering method ClickFix. Read our analysis of a recent campaign. Lampion malware distributors are now...
lampionbackclickfixlures
https://www.malwarebytes.com/blog/news/2026/04/clickfix-finds-new-way-to-infect-macs
ClickFix finds a new way to infect Macs | Malwarebytes
Apr 10, 2026 - ClickFix campaigns have found a way around macOS Tahoe's warnings against pasting commands in the Terminal. They're using Script Editor instead.
a new wayclickfixfindsinfectmacs
https://thehackernews.com/2025/09/from-mostererat-to-clickfix-new-malware.html?m=1
From MostereRAT to ClickFix: New Malware Campaigns Highlight Rising AI and Phishing Risks
MostereRAT phishing campaign targets Japanese users with advanced evasion tactics, disabling defenses and stealing data.
https://www.sophos.com/de-de/blog/i-am-not-a-robot-clickfix-used-to-deploy-stealc-and-qilin
I am not a robot: ClickFix used to deploy StealC and Qilin | SOPHOS
The fake human verification process led to infostealer and ransomware infections.
i am not a robot
https://unit42.paloaltonetworks.com/ja/tag/clickfix-ja/
ClickFix Archives - Unit 42
clickfixarchivesunit
https://clickfix.carsonww.com/
ClickFix Hunter
ClickFix Hunter - A public repository of malicious ClickFix domains.
clickfixhunter
https://unit42.paloaltonetworks.com/preventing-clickfix-attack-vector/?pdf=download&lg=en&_wpnonce=19daf64377
Fix the Click: Preventing the ClickFix Attack Vector
Aug 4, 2025 - ClickFix campaigns are on the rise. We highlight three that distributed NetSupport RAT, Latrodectus, and Lumma Stealer malware.
the clickfixpreventingattackvector
https://thehackernews.com/2026/01/clickfix-attacks-expand-using-fake.html?version=meter+at+null
ClickFix Attacks Expand Using Fake CAPTCHAs, Microsoft Scripts, and Trusted Web Services
ClickFix uses fake CAPTCHAs and a signed Microsoft App-V script to deploy Amatera stealer on enterprise Windows systems.
https://www.clickfix.fyi/
ClickFix.fyi - Learn About the ClickFix Scam
Informational site about the ClickFix malware scam and how to stay safe.
learn aboutclickfixfyiscam