ClearFake: Threat Cluster Using ClickFix Lures
ClearFake is a threat cluster known for compromising legitimate websites and planting fake CAPTCHA lures that use ClickFix-style social engineering decoys. It…
ClearFake is a threat cluster known for compromising legitimate websites and planting fake CAPTCHA lures that use ClickFix-style social engineering decoys. It…
Gen Threat Labs is a cybersecurity research entity that, along with Microsoft, highlighted ClearFake campaigns distributing WordlistLoader and Amatera Stealer using ClickFix…
Cybersecurity researchers have uncovered a novel campaign that abuses FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote…
Cybersecurity researchers have identified two new malware families, WordlistLoader and SynkLoader, which are being used to deliver next-stage payloads and potentially sell…
WordlistLoader is a malware family distributed through ClearFake campaigns using ClickFix lures. It is delivered via WebDAV servers and is often associated…
ACR Stealer, an infostealer active since 2024, is targeting enterprise networks by stealing saved browser passwords, live session tokens, PDFs, Microsoft 365…
Amatera Stealer is an information stealer distributed through ClearFake campaigns using ClickFix lures. It is often delivered alongside WordlistLoader via WebDAV servers.…
Security researcher Bert-Jan Pals analyzed roughly 3,000 live ClickFix payloads and presented findings at OrangeCon in early June, publishing details on June…
ClearFake is a campaign that uses compromised websites to display fake CAPTCHA prompts, leading to malware delivery via ClickFix. It leverages EtherHiding…
Expel is a cybersecurity company that detected the SynkLoader campaign via Microsoft Teams phishing and also noted the abuse of jsDelivr CDN…