#clickfix
5 articles
Across cryptocurrency, finance, and technology, five articles tagged ClickFix span 2026-04-10 to 2026-09-17. AMOS Stealer, ClickFix, and Lazarus Group appear among the top threat actors tracked in this coverage. Asia, Europe, and North america rank among the most affected regions. The severity mix comprises three high-severity items and one medium-severity item. These five articles examine activity tied to the listed actors across the affected sectors and regions during the stated date range.
HIGHClickFix Campaign Hijacks 100+ Ukrainian Sites to Spread Lunex
CERT-UA tracks UAC-0277: 100+ compromised Ukrainian sites serve fake Cloudflare checks that install Lunex Stealer and the LunarAxe browser extension.
HIGHAMOS Stealer Abuses Fake macOS Toolkit Guides
Unit 42's lab infection shows AMOS stealer pulling payloads from getmacouscloud[.]com and exfiltrating browser, wallet, and Telegram data to C2 161.35.146[.]120.
HIGHLazarus Hijacks macOS via ClickFix to Target Executives
Lazarus APT uses ClickFix social engineering to deliver macOS malware — fake browser update prompts trick executives into running AppleScript payloads that steal credentials and…
MEDIUMClickFix Mac Malware Campaign Uses Fake Apple Page to Deliver Payloads
A new ClickFix-style campaign targets macOS users with fake Apple instructions to run malicious commands.
HIGHClickFix Malware Campaign Evades macOS Defenses via Script Editor
A ClickFix social engineering campaign bypasses macOS security warnings by using Script Editor to execute malicious commands, marking a significant evolution in Mac-targeting malware.
Stay Updated
Get the latest cybersecurity news delivered to your inbox.