Install
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
ClickFix Crypto Scam Hides Its Command Server Inside Google Sheets
3+ day, 23+ hour ago (331+ words) The operation is a browser-based spin on the "ClickFix" social engineering trick, a new Cisco Talos report says. Instead of tricking targets into running operating system commands, the actors talk victims into pasting JavaScript directly into Chrome's address bar or…...
Hackers Abuse Real ChatGPT Links to Trick Windows Users Into Installing Malware
1+ week, 4+ day ago (689+ words) Windows users are being targeted through a malicious campaign that turns a ChatGPT shared link into the step of a malware infection. Rather than breaking into the AI platform, the operators place a deceptive message inside a shared conversation and…...
TerminalFix looks like ClickFix, but delivers a very different payload
1+ week, 4+ day ago (441+ words) Microsoft has published details about a Windows malware campaign it calls TerminalFix. The social engineering used to infect people is very similar to what we’ve seen in ClickFix campaigns. A website visitor is presented with a fake Cloudflare CAPTCHA which,…...
TerminalFix Uses Fake CAPTCHA, DLL Sideloading and Steganography to Breach Networks
1+ week, 6+ day ago (499+ words) Rather than delivering a conventional infostealer, the campaign builds persistent access and deploys a reverse-tunnel implant capable of turning an infected Windows endpoint into a proxy for reaching internal network resources. The intrusion begins on compromised websites displaying a convincing…...
TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
1+ week, 6+ day ago (372+ words) Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal or PowerShell. "While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply…...
Microsoft Warns TerminalFix ClickFix Campaign Uses Fake CAPTCHA to Deploy Reverse Tunnel
2+ week, 1+ day ago (462+ words) A TerminalFix campaign, a ClickFix variant, is using fake Cloudflare CAPTCHA prompts to trick users into executing PowerShell commands that install a reverse-tunnel implant. Documented by Microsoft, the activity targets organizations and can turn a compromised Windows device into a…...
ClickFix Campaigns Deploy PavinLoader With Blockchain-Based C2 and Amatera Stealer
2+ week, 4+ day ago (643+ words) ClickFix campaigns are turning routine web prompts into Windows infections. A tracked loader, PavinLoader, is delivered through fake verification pages, software downloads, and malicious game installers before pulling in malware. The activity makes victim part of the execution chain. A…...
PavinLoader Uses ClickFix and Fake Downloads to Deploy Amatera Stealer via Blockchain C2
2+ week, 5+ day ago (531+ words) The activity shows how attackers are moving beyond a single delivery vector. A victim may be lured to a fake Cloudflare or Google verification page and instructed to paste a command, persuaded to install apparently legitimate software, or tricked into…...
E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands
2+ week, 4+ day ago (708+ words) Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE. While threat actors are known to abuse legitimate services…...
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
2+ week, 5+ day ago (732+ words) Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups. According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka…...