Skip to content

other

ClickFix

A social-engineering technique using fake CAPTCHA or error prompts to trick users into pasting and running attacker commands, causing infection.

Known aliases

  • Click Fix
  • ClickFix campaign
  • ClickFix clipboard trap
  • ClickFix-style CAPTCHA
  • ClickFix-style lure
  • CrashFix
  • fake CAPTCHA gate
  • fake CAPTCHA lure
  • Malicious Copy and Paste
  • pastejacking

Relationships

No evidence-backed relationships are recorded.

Current stories

security8 publishers

Star Blizzard now sends its Ukraine lures from hacked WordPress and cPanel sites

Microsoft says Star Blizzard has sent fake event invitations to more than 100 organizations since January, many from hacked WordPress and cPanel sites. The group, long known for stealing email passwords, now uses the messages to install a Windows backdoor.

Perspective Coverage

8 publishers
Builder
Builder 28%
Operator
Operator 62%
Investor
Investor 10%

Reality

Evidence66
Adoption35
Hype gap+18
Incentives35
Confidence70
build1 publisher

Star Blizzard now delivers the CosmicPulse backdoor through fake event invitations

Microsoft says Russia's FSB-linked Star Blizzard sent fake event invitations to more than 100 organizations since January 2026. The lures pose as Chatham House and Atlantic Council events and carry a new Python backdoor, CosmicPulse, aimed at people working on Ukraine.

Publishers:dev.to

Reality

Evidence60
Adoption
Insufficient
Hype gap+20
Incentives
Insufficient
Confidence62
security3 publishers

Rapid7 counted 8,539 high-severity CVEs and 40 exploited ones. Patch coverage is now a vanity metric

Disclosures doubled year over year while actually-exploited vulnerabilities rose 8%. The arithmetic retires patch-everything SLAs and leaves exploitability triage as the defensible option.

Perspective Coverage

3 publishers
Builder
Builder 12%
Operator
Operator 76%
Investor
Investor 12%

Reality

Evidence62
Adoption
Insufficient
Hype gap+30
Incentives70
Confidence60
security4 publishers

Attackers move the ClickFix paste into Windows Terminal to land a multi-stage intrusion chain

Microsoft's TerminalFix writeup shows the same fake CAPTCHA lure now feeding multi-line PowerShell into Windows Terminal, where it sideloads a signed binary, pulls payloads out of PNG files and leaves a reverse tunnel behind.

Perspective Coverage

4 publishers
Builder
Builder 20%
Operator
Operator 75%
Investor
Investor 5%

Reality

Evidence65
Adoption
Insufficient
Hype gap+20
Incentives30
Confidence65
security3 publishers

Any local process can rewrite the dictation endpoint in Meta's new Muse assistant

Patrick Wardle published working code that sends Muse's dictated audio to a server of the attacker's choosing. Because the assistant holds file, microphone, camera, calendar and paired-iPhone access, whoever redirects it inherits all of it.

Perspective Coverage

3 publishers
Builder
Builder 33%
Operator
Operator 54%
Investor
Investor 13%

Reality

Evidence70
Adoption
Insufficient
Hype gap+20
Incentives45
Confidence65
security3 publishers

Attackers rewrote Brevo's embedded scripts at Cloudflare's edge with a hardcoded full-permission key

Brevo says a long-lived Cloudflare key with full account permissions sat in its application source code, and the Worker built with it stripped Content-Security-Policy headers from scripts that Sansec estimates reach 100,000 sites.

Perspective Coverage

3 publishers
Builder
Builder 34%
Operator
Operator 48%
Investor
Investor 18%

Reality

Evidence78
Adoption60
Hype gap+20
Incentives58
Confidence72

Earlier coverage

  1. Replayed session cookies bypassed the conditional access that blocked stolen passwords

    Security · September 10, 2026 · 1 publisher

  2. Talos found ClickFix operators moving their skimmer into a Tampermonkey userscript

    Product · September 8, 2026 · 1 publisher

  3. A loader on 5,400 hacked sites borrows the page's own CSP nonce to execute

    Build · September 5, 2026 · 1 publisher

  4. Recorded Future's half-year data shows adversaries continuing to favor abusing legitimate tools and trusted platforms already inside the enterprise

    Security · September 3, 2026 · 1 publisher

  5. Symantec finds attackers installing the signed Node.js runtime to run their payloads

    Security · September 3, 2026 · 1 publisher

  6. Attackers ran ClickFix into 47% of the initial access Microsoft logged last year

    Security · September 1, 2026 · 1 publisher

  7. A tampered Exodus installer hides a modular RAT behind a genuine wallet install

    Security · September 1, 2026 · 1 publisher

  8. CRPx0 climbed to 46 claimed victims in July on countdowns that fired in near unison

    Security · August 31, 2026 · 1 publisher

  9. ClickFix lures now paste an msiexec command that installs legitimate software to sideload a DLL

    Security · August 31, 2026 · 1 publisher

  10. Fake macOS troubleshooting posts route infostealers past Gatekeeper

    Leadership · August 31, 2026 · 1 publisher

  11. TerminalFix sends the fake CAPTCHA command to PowerShell so multi-line payloads survive

    Leadership · August 31, 2026 · 1 publisher

  12. ClickFix scales by asking employees to paste the command themselves

    Leadership · August 31, 2026 · 1 publisher

  13. Click-Exfil turns one pasted command into Claude Code account takeover

    Security · August 31, 2026 · 1 publisher

  14. Attackers bought five working browser extensions and shipped malware through auto-update

    Security · August 30, 2026 · 1 publisher

  15. Quishing moves the login off the managed laptop and onto an unfiltered personal phone

    Product · August 30, 2026 · 1 publisher

  16. Superior ships its wallet drainer as a routine auto-update to extensions users already trusted

    Build · August 30, 2026 · 1 publisher

  17. ClickFix operators moved the payload into text only the summarizer can see

    Build · August 30, 2026 · 1 publisher

  18. FTP welcome banners are the new dead drop, and that suits whoever reads netflow

    Security · August 25, 2026 · 1 publisher

  19. PavinLoader: the lures keep changing, the MSBuild stage does not

    Security · August 24, 2026 · 1 publisher

  20. Fake Codex installer outranks OpenAI in Google ads, then asks for a paste

    Product · August 24, 2026 · 1 publisher

  21. FTP greeting banners are now a C2 channel, and they are carrying two new RATs

    Security · August 21, 2026 · 2 publishers

  22. Check Point finds 2,000 hacked WordPress sites doing the hosting for a crypto-stealing toolkit

    Invest · August 21, 2026 · 2 publishers

  23. Sophos: Fake AI Installers Drove 30 of 38 AI-Linked MDR Cases, With Claude the Favourite Costume

    Security · August 21, 2026 · 1 publisher

  24. ClickFix in the sidebar: Def Con follow-up phishing turns a real Google Doc into the payload

    Security · August 20, 2026 · 2 publishers

  25. A year of Sophos AI cases: 30 of 38 were fake installers, not autonomous attackers

    Security · August 19, 2026 · 1 publisher

  26. C2Looper puts its C2 inside GitHub, and domain-reputation stacks will not care

    Security · August 18, 2026 · 1 publisher

  27. ClickFix operators install the signed Deno runtime to run their remote JavaScript

    Security · August 14, 2026 · 1 publisher

  28. Bring Your Own Runtime: Sophos MDR maps a repeatable Deno-based intrusion chain

    Security · August 14, 2026 · 1 publisher