SmartApeSG Campaign Exploits ClickFix Fake Verification Pages to Deliver NetSupport RAT
The SmartApeSG campaign is using ClickFix scripts disguised as fake browser verification pages to deploy a two-stage infection chain, culminating in a persistent NetSupport Manager RAT installation on...
ClickFix Evolves: Attackers Combine Social Engineering With Decade-Old PySoxy SOCKS5 Proxy for Persistent Access
A new ClickFix campaign observed by ReliaQuest pairs the social engineering technique with PySoxy, a 10-year-old Python SOCKS5 proxy, creating a two-channel persistent access chain that continues operating...
InstallFix: Hackers Use Fake Claude AI Installer Pages and Google Ads to Deploy RedLine Stealer Malware
A malware campaign called InstallFix is using paid Google Ads to push fake Claude AI installation pages to the top of search results, tricking users into running malicious...
The Sophisticated ClickFix Sting: How Calisto Disguises Itself to Steal Credentials
Calisto, a cyberespionage campaign attributed to the Russian FSB’s Center 18 for Information Security (military unit 64829), has been making waves in the cybersecurity community. This group has...
ClickFix: Fake Windows Updates and PNG Steganography Make a Darker Play for User Machines
For those deeply involved with cybersecurity, the past few years have seen a dramatic rise in sophisticated phishing campaigns leveraging social engineering to deliver malware onto unsuspecting victims....
SmartApeSG: the persistent evolution of a ClickFix-based RAT campaign
The SmartApeSG campaign, previously identified by aliases like ZPHP and HANEY MANEY, continues to demonstrate a remarkable capacity for adaptation, moving beyond initial tactics of deceptive browser update...
Malware, ClickFix attack variant using Silk Road founder as lure
In a striking development in the cyber threat landscape, a new ClickFix attack variant has emerged, utilizing the recent pardon of Silk Road founder Ross Ulbricht as bait...