ClearFake: Threat Cluster Using ClickFix Lures
ClearFake is a threat cluster known for compromising legitimate websites and planting fake CAPTCHA lures that use ClickFix-style social engineering decoys. It…
ClearFake is a threat cluster known for compromising legitimate websites and planting fake CAPTCHA lures that use ClickFix-style social engineering decoys. It…
Cybersecurity researchers have uncovered a novel campaign that abuses FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote…
Cybersecurity researchers have identified two new malware families, WordlistLoader and SynkLoader, which are being used to deliver next-stage payloads and potentially sell…
WordlistLoader is a malware family distributed through ClearFake campaigns using ClickFix lures. It is delivered via WebDAV servers and is often associated…
WebDAV was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
A malware operator left its delivery server exposed, allowing Rapid7 to recover a full toolkit of 1,048 files including lure templates, filename-spoofing…
A critical vulnerability (CVSS 8.8) in Windows WebDAV that allows attackers to hijack the working directory of signed binaries, leading to remote…
A threat actor documented by Check Point, associated with the WebDAV hijack technique (CVE-2025-33053) used in this campaign.
A malware campaign using WebDAV shares to deliver infostealers and RATs, leveraging AI-assisted tooling and multiple CVEs.
Amatera Stealer is an information stealer distributed through ClearFake campaigns using ClickFix lures. It is often delivered alongside WordlistLoader via WebDAV servers.…