Technology
ClickFix
ClickFix is a phishing kit, a software framework that enables cybercriminals to easily create and deploy phishing websites to steal user credentials.
Why it’s in the news: It is in the news because it has been adopted by sophisticated threat groups like Star Blizzard and is being combined with AI tools like ChatGPT to launch more advanced malware attacks.
Latest on ClickFix
- ClickFix Attacks Evolve to Better Hide Malicious Payloads
- ClickFix Attack Hides VBScript Payload in Browser Cache
- Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net
- Attackers Combine ChatGPT Feature Abuse With ClickFix to Deliver Trojan Malware
- Hackers Use ChatGPT Custom GPTs in ClickFix Attacks
- Documentation placeholder domain used in ClickFix attacks
- Attackers combined feature abuse of ChatGPT with a tool called ClickFix to distribute the malware.
- Threat actors are exploiting Google Ads, GitLab pages, and Claude's shared chat feature to distribute malware through ClickFix social engineering attacks.
- Attackers weaponized Claude's shared chat feature—the same convenience that was supposed to democratize AI access—to distribute malware at scale through social engineering.
- The campaign leverages the trust users place in established platforms to increase the effectiveness of the attacks.
- Victims are deceived into copying and pasting malicious code, which compromises their devices.
- Malware Pivots to ClickFix Delivery
Connections
17 entities linked to ClickFix across the news graph.
Under pressure from (7)