← Back
MalwareMalwarebytes Labs·5 hours ago

TerminalFix looks like ClickFix, but delivers a very different payload

Threat actors have adapted the ClickFix social engineering technique to create TerminalFix, which uses a similar fake CAPTCHA lure but delivers a payload designed to provide attackers with broader network access. Unlike the original ClickFix scheme, this variant escalates the threat from individual device compromise to potential lateral movement across enterprise networks. Security professionals should be alert to this evolution of a known attack pattern and educate users to recognize these deceptive prompts.

Read full article at Malwarebytes Labs

Related Articles

MalwareThe Hacker News·3 hours ago

13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices. "The injected code runs two operations against a site's visitors: a mobile ad-fraud and gambling-redirect

MalwareDark Reading·3 hours ago

ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain

The ClickFix campaign has compromised 31 organizations by leveraging the Polygon blockchain as an infrastructure tool, specifically using EtherHiding to dynamically update command-and-control servers. By abusing the blockchain as an attacker-controlled address book, the threat actors can maintain persistent communication channels that are difficult to disrupt through traditional takedown methods.

MalwareThe Hacker News·4 hours ago

Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

Iranian threat actor Nimbus Manticore has been observed impersonating recruiters to distribute previously undocumented cross-platform remote access trojans targeting Linux and macOS systems alongside Windows infrastructure. The malware families, developed using Node.js and JavaScript, represent an expansion of the group's toolset and delivery tactics, leveraging fake coding assessments as a social engineering vector. This campaign demonstrates the actor's effort to broaden its operational capabilities across multiple operating systems.