Terms

ClickFix

Follow the latest coverage, related explainers and connected technology stories.

Latest coverage

CN
Russian Star Blizzard Group Uses RedFlick Technique to Install CosmicPulse Malware

Russian Star Blizzard Group Uses RedFlick Technique to Install CosmicPulse Malware

Microsoft researchers observed a new delivery technique used by the Russian Star Blizzard group to deploy the CosmicPulse backdoor through phishing messages and malicious shortcut files. The campaigns, which targeted more than 100 organizations, enabled the infection chain to run with minimal victim involvement.

CN
Microsoft: Star Blizzard Develops Phishing Campaigns Using RedFlick Technique

Microsoft: Star Blizzard Develops Phishing Campaigns Using RedFlick Technique

Microsoft observed the Russia-linked Star Blizzard group shifting to broader phishing campaigns and using compromised websites and the RedFlick technique to deploy the CosmicPulse backdoor with less victim interaction. The campaigns targeted more than 100 organizations, including government entities, nongovernmental organizations, and research centers associated with support for Ukraine.

CN
Cybercriminals Exploit Custom GPTs to Execute ClickFix Attacks and Deploy Remote-Access Malware

Cybercriminals Exploit Custom GPTs to Execute ClickFix Attacks and Deploy Remote-Access Malware

A malicious campaign exploited custom versions of ChatGPT to direct users to fake pages asking them to run PowerShell commands, leading to the deployment of a remote-access Trojan. Huntress observed at least 40 connections to the malicious page, confirming two infections linked to a custom GPT.

CN
MacSync Malware Exploits Public iCloud Calendars to Distribute New Malicious Payloads

MacSync Malware Exploits Public iCloud Calendars to Distribute New Malicious Payloads

Attackers have developed a method to distribute the MacSync information-stealing malware by hiding commands inside public iCloud calendar events, while adding a backdoor that impersonates Finder and enables command execution and data theft from macOS devices.

CN
A Common Placeholder Domain in Developer Documentation Turns into a ClickFix Trap for Windows Users

A Common Placeholder Domain in Developer Documentation Turns into a ClickFix Trap for Windows Users

The domain third-party.com, used for years as a default address in programming documentation and code examples, has begun displaying a fake Cloudflare page that pressures Windows users into executing malicious PowerShell commands. There are no confirmed reports that the attack succeeded, but the domain’s prevalence in public repositories and projects makes it a potential danger for code copied verbatim.

CN
Brevo Supply Chain Breach Injects ClickFix Malware into Customer Websites

Brevo Supply Chain Breach Injects ClickFix Malware into Customer Websites

Brevo confirmed that attackers stole an API key for its Cloudflare account and used it to modify the content of its websites and JavaScript files embedded in customer websites, resulting in the distribution of ClickFix pages and malware. The campaign included adding a persistent backdoor to some WordPress sites, while the company said its application interface, customer data, and email delivery infrastructure were not affected.