Tech News
← Home  ·  All topics

Clickfix

14 GoKawiil briefs on this topic

Brevo breach used stolen Cloudflare API key to push ClickFix malware to sites

Brevo disclosed that hackers obtained a hardcoded, full-permission Cloudflare API key and used it to deploy a rogue Cloudflare Worker that rewrote content at the CDN edge for roughly 5.5 hours on September 14. The tampered scripts, including Brevo's forms widget, Conversations tool and SDK loader embedded on customer sites, were altered to serve ClickFix malware while stripping security headers to evade detection.

Hackers hijack HBO Max's Reddit account to spread ClickFix malware ads

Security researchers say attackers compromised HBO Max's official Reddit account and used it to post hundreds of fake ads linking to a lookalike site that runs a ClickFix scam. The scheme tricks visitors into copying and pasting a malicious command into their Terminal or Command Prompt, which silently installs info-stealing malware. Warner Bros. Discovery has not responded to requests for comment, and it's unclear how many users were affected.

Homebrew 7.0.0 adds native BrewUI app and a built-in vulnerability scanner

Homebrew, the widely used macOS package manager, has shipped version 7.0.0 with a fully released BrewUI graphical interface for macOS 26 'Tahoe' and later, letting users browse packages and dependencies visually instead of via command line. The update also introduces a new 'brew vulns' command backed by a Homebrew-specific advisory database, which cross-references installed formulae against OSV.dev vulnerability records.

HBO Max's verified Reddit account hijacked to spread ClickFix malware

Attackers took over HBO Max's official, verified Reddit account and used it to post 108 malicious ads over roughly two days, tricking Windows and macOS users into installing information-stealing malware. The ads used the ClickFix technique, luring victims into pasting attacker-supplied commands into Run, PowerShell, or Terminal under the guise of fixing errors or verifying CAPTCHAs, with some posts impersonating a fake HBO Max app and others posing as AI tools or developer utilities.

ClickFix social engineering attacks spread across Windows and macOS

Security researchers report that ClickFix-style attacks, which trick users into copying and running malicious commands via fake CAPTCHA pop-ups, are proliferating across both Windows and Mac systems. Researcher Kevin Beaumont notes victims are flooding Reddit for help, and attackers are now compromising legitimate websites to embed these prompts, making the scam harder to spot.

ClickFix scam using fake CAPTCHAs spreads rapidly across PCs and Macs

Security researchers report that ClickFix, a malware technique relying on fake CAPTCHA prompts and terminal commands, has exploded in popularity among attackers, including state-backed hacking groups. The attack tricks victims into copying and pasting a malicious command into Windows Run, PowerShell, or macOS Terminal after clicking through a fraudulent verification screen on a compromised website.

Cisco Talos Uncovers Two ClickFix Campaigns Exploiting Google Sheets and Trusted Services

Cisco Talos researchers identified two separate ClickFix-style social engineering campaigns that trick victims into executing malicious code themselves, one aimed at stealing cryptocurrency and another designed to gain persistent enterprise network access. One campaign uses a publicly shared Google Sheet to distribute malicious browser code that hijacks Chrome transaction interfaces, while both operations abuse legitimate cloud services and trusted software to disguise malicious activity as normal user behavior.

5,400+ hacked WordPress and PrestaShop sites push ClickFix malware via BNB Smart Chain

Netskope researchers found over 5,400 compromised small-business websites, mostly running WordPress and PrestaShop, injected with scripts that fetch malicious payloads from smart contracts on the BNB Smart Chain Testnet. Visitors are shown a fake CAPTCHA that tricks them into pasting a PowerShell command via the Windows Run dialog, which downloads and runs the attacker's final payload. Later in the campaign, attackers swapped the ClickFix payload for a stealthier WebRTC data-channel stager that opens a covert encrypted connection without a genuine handshake.

Microsoft flags TerminalFix, a fake-CAPTCHA malware campaign targeting Windows users

Microsoft has identified a malware campaign named TerminalFix that mimics Cloudflare and other trusted verification pages to trick Windows users into pasting commands into PowerShell or Command Prompt. Unlike earlier ClickFix attacks that used the Run dialog for simpler commands, TerminalFix's terminal-based approach lets attackers run longer, multi-stage scripts that establish persistent proxy access into a victim's machine and network.

31 Organizations Hit in ClickFix Attack Using Polygon Blockchain to Hide C2 Servers

GuidePoint Security's research team found that attackers have breached at least 31 organizations—spanning e-commerce, professional services, and retail logistics—using a ClickFix campaign that leverages the Polygon blockchain to conceal command-and-control infrastructure. The technique, dubbed EtherHiding, lets attackers dynamically update C2 server locations via blockchain transactions instead of relying on a single fixed address.

Microsoft details 'TerminalFix' ClickFix variant targeting enterprise networks via PowerShell

Microsoft has identified a new ClickFix-style social engineering campaign called TerminalFix, which uses fake Cloudflare CAPTCHA prompts to trick users into pasting malicious commands into Windows Terminal or PowerShell. Once executed, the command triggers a multi-stage attack chain designed to give attackers a persistent foothold inside enterprise systems.

Microsoft flags TerminalFix, a ClickFix variant using PowerShell for reverse network tunnels

Microsoft has identified a new ClickFix-style attack called TerminalFix that uses fake Cloudflare CAPTCHA pages on compromised websites to trick users into pasting and running malicious PowerShell commands in Windows Terminal. Rather than deploying simple infostealers, the campaign runs a multi-stage chain that hides payloads inside PNG images via steganography, establishes persistence through scheduled tasks and registry keys, and ultimately installs a custom Python-based reverse tunnel into the victim's internal network.