Tag

Clickfix

All articles tagged with #clickfix

Malicious Custom GPTs on ChatGPT.com Lure Users into Installing Remote Access Trojans
cybersecurity6 days ago

Malicious Custom GPTs on ChatGPT.com Lure Users into Installing Remote Access Trojans

A new scam uses sponsored Google ads to direct users to malicious Custom GPTs on the legitimate chatgpt.com domain. These fake interfaces display a 'Service Availability Notice' and link to a Google Sites page mimicking a Cloudflare check. The page instructs users to run PowerShell commands, installing a remote access trojan (RAT) via signed applications. Huntress confirmed at least 40 incidents, with OpenAI removing the first instance by September 25, 2026. Experts warn that trusted domains like ChatGPT and Google are being abused to bypass security awareness, urging users to never paste commands into terminals as a verification step.

Attackers Weaponize ChatGPT Custom GPTs to Deploy RATs via ClickFix
cybersecurity8 days ago

Attackers Weaponize ChatGPT Custom GPTs to Deploy RATs via ClickFix

Threat actors are abusing ChatGPT Custom GPTs to deliver remote access trojans (RATs) through ClickFix lures. Huntress identified a campaign where malicious GPTs, hosted on the legitimate chatgpt.com domain, redirect users to fake Cloudflare CAPTCHA pages. These pages trick victims into executing PowerShell commands that install malware. The infection chain uses signed binaries to sideload malicious DLLs, ultimately deploying a RAT capable of data theft, surveillance, and network persistence. At least 40 users have been infected, with the initial entry point often being sponsored Google ads for 'chatgpt'.

Widely Used Developer Placeholder Domain third-party.com Now Hosts ClickFix Malware
cybersecurity15 days ago

Widely Used Developer Placeholder Domain third-party.com Now Hosts ClickFix Malware

The domain third-party.com, a common placeholder in developer documentation, is now serving a fake Cloudflare verification page that tricks Windows users into executing malicious PowerShell commands. This ClickFix attack exploits the fact that the domain is not reserved for documentation like example.com, allowing attackers to hijack it for malware distribution. While the current payload is broken, the infrastructure remains live, posing a risk if reactivated.

ClickFix Attacks Move to Mainstream with Fake CAPTCHA Tactics
technology28 days ago

ClickFix Attacks Move to Mainstream with Fake CAPTCHA Tactics

ClickFix has become a mainstream malware delivery method that tricks users into pasting a single malicious command from a fake CAPTCHA overlay on compromised sites, bypassing code-signing and Gatekeeper protections and enabling infections on Windows and macOS; campaigns span Google Sheets-based control and blockchain-hosted infrastructure, with about 5,400 sites involved, but defenders like BlockBlock and uBlock offer mitigations, and researchers urge awareness over user-blaming.

Ghost CMS flaw spawns 700-site ClickFix loader campaign
technology4 months ago

Ghost CMS flaw spawns 700-site ClickFix loader campaign

Threat actors exploited Ghost CMS CVE-2026-26980, a critical Content API SQL injection, to steal Admin API keys and inject malicious JavaScript across 700+ sites, enabling two-stage payload delivery for ClickFix-style fake CAPTCHA attacks; a patch (Ghost 6.19.1) was released in February 2026, and victims span universities, blockchain, SaaS, media, and finance. Remediation: upgrade, rotate credentials, audit access logs, and alert users who visited affected sites.

Global Ghost CMS flaw exploited to steal admin keys and push ClickFix scam
security4 months ago

Global Ghost CMS flaw exploited to steal admin keys and push ClickFix scam

A widespread campaign abused a critical Ghost CMS SQL injection (CVE-2026-26980) affecting versions 3.24.0–6.19.0 to read database data and steal admin API keys, then injects malicious JavaScript into articles. The loader fetches a second-stage payload that triggers a fake Cloudflare prompt and a ClickFix lure, leading victims to a Windows command prompt instruction and subsequent malware downloads. High-profile targets (Harvard, Oxford, Auburn, DuckDuckGo) were affected. Ghost released fix 6.19.1 on Feb 19, but many sites have not updated. Action items: upgrade to 6.19.1+, rotate all exposed keys, and review up to 30 days of admin API call logs to identify IoCs and remove injected scripts.

Kash Patel’s Based Apparel Site Used as Mac Malware Lure with Fake Cloudflare Page
technology4 months ago

Kash Patel’s Based Apparel Site Used as Mac Malware Lure with Fake Cloudflare Page

Security researchers flag BasedApparel.com, Kash Patel’s apparel site, for hosting a ClickFix-style scam that shows a fake Cloudflare warning on macOS and instructs users to copy-paste a Terminal command. The copied text decodes to a hidden shell script that downloads malware capable of stealing browser credentials and crypto-wallet data, exfiltrating it to a hacker-controlled domain. The attack highlights how compromised legitimate sites can deliver infostealers via scareware, and Apple has added protections in macOS 26.4 against pasted Terminal commands; Based Apparel did not comment.

MacSync Infostealer Lures Mac Users Through ClickFix Social-Engineering Campaigns
technology6 months ago

MacSync Infostealer Lures Mac Users Through ClickFix Social-Engineering Campaigns

Three ClickFix campaigns have been found delivering the macOS infostealer MacSync by tricking users into pasting Terminal commands to download and run a shell script that fetches the payload and exfiltrates credentials, keychains, and seed phrases. The campaigns (Nov 2025 using OpenAI Atlas bait via Google ads; Dec 2025 via ChatGPT-related pages; Feb 2026 with a new variant) rely on social-engineering lures, malvertising, and trusted platforms to disguise malicious commands and payloads, with in-memory AppleScript execution to evade detection. Defenders are urged to patch hosting platforms (e.g., WordPress), monitor for ClickFix/trojan lures, and maintain zero-trust principles as attackers adapt tactics.

DNS Channel Used to Deliver PowerShell Payload in ClickFix Attacks
technology7 months ago

DNS Channel Used to Deliver PowerShell Payload in ClickFix Attacks

A new ClickFix variant uses a DNS-based delivery channel: victims are prompted to run nslookup in the Run dialog, querying an attacker-controlled DNS server. The DNS response contains a PowerShell payload that, when executed, downloads a ZIP with a Python runtime and malware scripts, establishes persistence, and installs ModeloRAT. This marks the first known use of DNS for staging and delivering ClickFix payloads, enabling on-the-fly payload updates and blending with normal DNS traffic instead of relying on HTTP.

ClickFix Threat Evolves, Signaling New Wave of Malicious Copy-and-Paste Attacks
security11 months ago

ClickFix Threat Evolves, Signaling New Wave of Malicious Copy-and-Paste Attacks

ClickFix is a sophisticated scam campaign targeting Windows and macOS users by exploiting trust in online travel bookings and using social engineering tactics, such as fake CAPTCHA prompts and device-adaptive payloads, to infect devices with malware like PureRAT. The attacks leverage native OS capabilities and often bypass security tools, making awareness and cautious behavior the best defenses, especially during holiday gatherings when family members may be less vigilant.

FileFix and ClickFix Attacks Surge in 2025, ESET Reports
cybersecurity1 year ago

FileFix and ClickFix Attacks Surge in 2025, ESET Reports

The article discusses a 517% rise in ClickFix social engineering attacks using fake CAPTCHA verifications, leading to various malware infections, and introduces a new method called FileFix that tricks users into executing malicious commands via file paths. It also highlights recent phishing campaigns exploiting domains, email lures, and legitimate platforms to steal personal information and control victims' devices.