Tag
high
advisory
ClickFix Campaign Activity
16 IOCsTracking brief for the ClickFix campaign; individual sightings are folded in as reported.
PoC
open source packages +36
campaign
clickfix
16i
updated
high
advisory
ClickFix Campaign Targets macOS Users with Infostealers via Fake Utility Fixes
2 rules 5 TTPs 5 IOCsThe ClickFix campaign targets macOS users with fake utility fixes, tricking them into running malicious Terminal commands to install infostealing malware such as Macsync, Shub Stealer, and AMOS.
Microsoft Security Blog +2
macos
infostealer
clickfix
terminal
2r
5t
5i
high
advisory
ClickFix 'BackgroundFix' Campaign Delivers CastleLoader, NetSupport RAT, and CastleStealer
2 rules 3 TTPs 1 IOCThe 'BackgroundFix' ClickFix campaign uses social engineering to trick victims into downloading malware disguised as a free image-editing tool, leading to the deployment of CastleLoader, NetSupport RAT for remote access, and CastleStealer for credential theft.
Microsoft Windows +2
clickfix
malware
social-engineering
rat
infostealer
castleloader
netsupport
2r
3t
1i
high
advisory
DeepLoad Malware Distributed via ClickFix
2 rules 3 TTPsThe DeepLoad malware steals credentials, installs malicious browser extensions, spreads via USB drives, and is being distributed via ClickFix campaigns using PowerShell loaders.
deepload
clickfix
credential-theft
windows
2r
3t