Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > clickfix
#clickfix

For $250 a Month, Anyone Can Rent a Fully Featured Windows Spy Tool Called VectraRAT

17 September 2026  |  dark6  |  Malware

Researchers have uncovered VectraRAT, a subscription-based remote access trojan renting for as little as $250 a month that gives buyers keylogging, hidden-desktop control, and credential theft on infected...

>> read more

ClearFake CAPTCHA Campaign Disables EDR to Deploy Crypto Stealer

10 September 2026  |  dark6  |  Malware

ClearFake has expanded its fake CAPTCHA operation with a vulnerable-driver technique that terminates endpoint defenses before deploying a cryptocurrency stealer. The campaign combines compromised sites, blockchain-hosted instructions, WebDAV...

>> read more

Fake macOS Update Screens Are Tricking Mac Users Into Handing Over Crypto Wallets

1 August 2026  |  dark6  |  Malware

A North Korea-linked campaign is using fake 'Installing System Update' overlays to trick victims into pasting malicious commands into Terminal, deploying a backdoor that raids 157 cryptocurrency wallets...

>> read more

Fake CAPTCHA Pages Are Now Tricking Mac Users Into Installing Password-Stealing Malware

30 July 2026  |  dark6  |  Malware

Kaspersky has documented a ClickFix campaign now targeting macOS users, luring them into pasting a Terminal command that quietly installs Atomic Stealer (AMOS). The malware harvests browser passwords,...

>> read more

SmartApeSG Campaign Exploits ClickFix Fake Verification Pages to Deliver NetSupport RAT

2 June 2026  |  dark6  |  Malware

The SmartApeSG campaign is using ClickFix scripts disguised as fake browser verification pages to deploy a two-stage infection chain, culminating in a persistent NetSupport Manager RAT installation on...

>> read more

ClickFix Evolves: Attackers Combine Social Engineering With Decade-Old PySoxy SOCKS5 Proxy for Persistent Access

14 May 2026  |  dark6  |  Malware

A new ClickFix campaign observed by ReliaQuest pairs the social engineering technique with PySoxy, a 10-year-old Python SOCKS5 proxy, creating a two-channel persistent access chain that continues operating...

>> read more

InstallFix: Hackers Use Fake Claude AI Installer Pages and Google Ads to Deploy RedLine Stealer Malware

10 May 2026  |  dark6  |  Malware

A malware campaign called InstallFix is using paid Google Ads to push fake Claude AI installation pages to the top of search results, tricking users into running malicious...

>> read more

The Sophisticated ClickFix Sting: How Calisto Disguises Itself to Steal Credentials

5 December 2025  |  dark6  |  Spyware

Calisto, a cyberespionage campaign attributed to the Russian FSB’s Center 18 for Information Security (military unit 64829), has been making waves in the cybersecurity community. This group has...

>> read more