Patrick Wardle found that any local process on a Mac can redirect Meta Muse's voice endpoint and capture its account token, with no macOS permission needed. Muse also zipped and exported the 6.8 GB root filesystem of its own sandbox on request.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence40
Sophos linked ClickFix lures that open Windows Terminal, not the Run dialog, to STAC4924, a campaign it has tracked since at least March. The intrusions plant Lorem Ipsum Loader and a Python reverse-tunnel implant that relays attacker traffic through the victim host.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap−5
- Incentives
- Insufficient
- Confidence58
Check Point Research says exposed directories revealed the logs, source code and management tooling behind StopAndProtect, a campaign it links to more than 5,000 infected machines.
Perspective Coverage
3 publishers
- Builder
- Builder 30%
- Operator
- Operator 63%
- Investor
- Investor 7%
Reality
- Evidence62
- Adoption30
- Hype gap+10
- Incentives55
- Confidence65
Microsoft's TerminalFix writeup shows the same fake CAPTCHA lure now feeding multi-line PowerShell into Windows Terminal, where it sideloads a signed binary, pulls payloads out of PNG files and leaves a reverse tunnel behind.
Perspective Coverage
4 publishers
- Builder
- Builder 20%
- Operator
- Operator 75%
- Investor
- Investor 5%
Reality
- Evidence65
- Adoption
- Insufficient
- Hype gap+20
- Incentives30
- Confidence65
Cisco Talos traces a crypto skimmer running since October 2025 that keeps persistence in a Tampermonkey userscript and pulls its code from a public Google Sheet. Talos says most organisations are not the target.
Reality
- Evidence66
- Adoption20
- Hype gap−12
- Incentives55
- Confidence58
The Threat Hunter Team says the technique has hit government departments, technology firms and hotels since February 2026. In one case, the operators moved to node.exe only after their Cobalt Strike beacons kept getting blocked.
Reality
- Evidence57
- Adoption58
- Hype gap+16
- Incentives66
- Confidence56
Bitdefender puts 84% of its high-severity incidents on binaries that were already installed on the host. That figure and Microsoft's ClickFix number cover the two largest volume plays in the telemetry, and both sit outside what attachment scanning and patch cycles reach.
Reality
- Evidence55
- Adoption72
- Hype gap+15
- Incentives72
- Confidence58
Bitdefender logged 873 claimed ransomware victims in July, the third-highest month in a year. A brand that barely existed in June supplied 46 of them, on a leak site the analysts say they cannot fully verify.
Publishers:bitdefender.com
Reality
- Evidence38
- Adoption26
- Hype gap+42
- Incentives64
- Confidence44
Field Effect logged three ClickFix chains between mid-June and July 2026, two of them landing on the same hidden file pair in ProgramData, and in one case the operator phoned the victim to open the lure.
Publishers:fieldeffect.com
Reality
- Evidence60
- Adoption34
- Hype gap−8
- Incentives58
- Confidence55
Microsoft says the campaign now delivers its payload through a command pasted into Terminal rather than a .dmg installer. The review step that mattered was tied to that older delivery method, and the attackers no longer need it.
Reality
- Evidence64
- Adoption52
- Hype gap+8
- Incentives68
- Confidence60
Microsoft Threat Intelligence says this ClickFix variant ends in Active Directory reconnaissance and a reverse-tunnel implant, giving a single tricked employee a route into the network.
Reality
- Evidence55
- Adoption35
- Hype gap+15
- Incentives70
- Confidence60
Socket says the operators bought their way onto tens of thousands of machines and delivered the payload in a routine update. Cleanup means rotating passwords and moving crypto to fresh wallets, user by user.
Reality
- Evidence52
- Adoption34
- Hype gap+12
- Incentives62
- Confidence50
An extension allowlist pins an ID, and the ID survives a sale. The operators behind Superior bought or seeded trust that users had already granted, then spent it in an automatic update that stripped page CSP on the way through.
Reality
- Evidence55
- Adoption40
- Hype gap+12
- Incentives55
- Confidence50
Forcepoint's X-Labs found short-lived ClickFix domains carrying white-on-white characters and zero-width spaces, which puts the trust boundary for any agent you point at the open web inside your own extraction code.
Publishers:forcepoint.com
Reality
- Evidence30
- Adoption22
- Hype gap+40
- Incentives75
- Confidence38
Malwarebytes traces one loader through ClickFix prompts, malicious game installs and fake software downloads. The shared part is a .csproj-to-MSBuild handoff and a blockchain lookup for C2.
Reality
- Evidence66
- Adoption52
- Hype gap−8
- Incentives58
- Confidence61
Cato says a sponsored result for "codex macos download" leads to a Google Sites clone whose Terminal command strips quarantine flags and stages an AMOS-linked payload.
Reality
- Evidence58
- Adoption34
- Hype gap+12
- Incentives66
- Confidence57
The StopAndProtect campaign keeps its payloads, command channel and stolen-file storage on other people's blogs. That makes domain reputation a weaker signal, and cleanup somebody else's bill.
Reality
- Evidence66
- Adoption68
- Hype gap+14
- Incentives61
- Confidence64
Huntress says a researcher targeted after Black Hat and Def Con was sent a Google Doc that rendered an Apps Script sidebar with ClickFix instructions. The lure arrived by DM, not email.
Reality
- Evidence68
- Adoption34
- Hype gap+14
- Incentives62
- Confidence66
Sophos X-Ops confirmed 38 AI-related MDR cases across twelve months. Impersonation of AI software accounted for 30 of them, and conventional payload controls were what stopped them.
Reality
- Evidence62
- Adoption54
- Hype gap−12
- Incentives68
- Confidence57
Jamf Threat Labs describes a Rust stealer that copies Chromium profiles and drives them over Chrome DevTools Protocol. Password rotation does not revoke what it exports.
Reality
- Evidence64
- Adoption18
- Hype gap+14
- Incentives52
- Confidence58