⤷ Title: ClickLock Stealer Locks macOS Screens Until Victims Hand Over Their Password
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 06:26:00 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #ClickLock Stealer #crypto wallet #Group_IB #GSocket #Infostealer #macOS Malware #Telegram C2
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 06:26:00 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #ClickLock Stealer #crypto wallet #Group_IB #GSocket #Infostealer #macOS Malware #Telegram C2
Daily CyberSecurity
ClickLock Stealer Locks macOS Screens Until Victims Hand Over Their Password
At a glance Malware family ClickLock Stealer (new, named by Group-IB) Threat actor Unattributed. No actor or group named. Target / victims macOS users, especially crypto holders. At least 100 vict…
⤷ Title: TELEPUZ Malware Spreads Through ClickFix and VIDAR Attacks
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 14:57:42 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #Elastic Security Labs #Infostealer #MaaS #TELEPUZ #Vidar #WebInject
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 14:57:42 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #Elastic Security Labs #Infostealer #MaaS #TELEPUZ #Vidar #WebInject
Daily CyberSecurity
TELEPUZ Malware Spreads Through ClickFix and VIDAR Attacks
At a glance Malware family TELEPUZ Threat actor Unnamed; suspected solo developer or small team running a MaaS Target / victims Windows users reached through compromised web pages Delivery vector …
⤷ Title: Starland RAT Campaign by Russian-Speaking Actor UAT-11795 Targets Crypto Users in the US and Europe
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 22 Jul 2026 13:58:09 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CASTLESTEALER #Cisco Talos #ClickFix #Cryptocurrency Theft #Remcos RAT #Starland RAT #Telegram C2 #UAT_11795 #WLDR Agent
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 22 Jul 2026 13:58:09 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CASTLESTEALER #Cisco Talos #ClickFix #Cryptocurrency Theft #Remcos RAT #Starland RAT #Telegram C2 #UAT_11795 #WLDR Agent
Daily CyberSecurity
Starland RAT Campaign by Russian-Speaking Actor UAT-11795 Targets Crypto Users in the US and Europe
At a glance Actor / group UAT-11795 (suspected Russian-speaking, financially motivated) Activity type Credential and cryptocurrency theft via trojanized software installers Targets / victims Windo…
⤷ Title: ACR Stealer Spreads Through ClickFix Lures in Two Attack Chains
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 06:40:20 +0000
════════════════════════
⌗ Tags: #Malware #ACR Stealer #ClickFix #Credential Theft #EtherHiding #Infostealer #Malware_as_a_Service #Microsoft Defender #powershell
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 06:40:20 +0000
════════════════════════
⌗ Tags: #Malware #ACR Stealer #ClickFix #Credential Theft #EtherHiding #Infostealer #Malware_as_a_Service #Microsoft Defender #powershell
Daily CyberSecurity
ACR Stealer Spreads Through ClickFix Lures in Two Attack Chains
At a glance Malware family ACR Stealer (infostealer; linked to a rebrand of Amatera Stealer) Threat actor No named actor; sold via malware-as-a-service (MaaS) Target / victims Enterprise Windows e…
⤷ Title: TAG-150 Attack Chain Deploys DenoRAT Malware
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 08:01:09 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #DenoRAT #malware #NightshadeC2 #TAG_150
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 08:01:09 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #DenoRAT #malware #NightshadeC2 #TAG_150
Daily CyberSecurity
TAG-150 Attack Chain Deploys DenoRAT Malware
A recent cyberattack targeted a financial institution using a ClickFix social engineering lure. This incident revealed an evolving TAG-150 attack chain. Security researchers from eSentire Threat R…
⤷ Title: TAG-195 Deploys ChonkyChicken Modular Malware Framework
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Sun, 26 Jul 2026 14:45:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ChonkyChicken #ClickFix #Malware_as_a_Service #TAG_195 #TinyEgg
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Sun, 26 Jul 2026 14:45:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ChonkyChicken #ClickFix #Malware_as_a_Service #TAG_195 #TinyEgg
Information Security News
TAG-195 Deploys ChonkyChicken Modular Malware Framework
Evolution of the Golden Chickens Ecosystem Cybercriminals operating within the TAG-195 ecosystem have fundamentally restructured their malware architecture, adopting a highly modular approach. Con…
⤷ Title: Fake Job Interviews Deliver PylangGhost and GolangGhost RATs to Crypto Workers
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 28 Jul 2026 06:11:37 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ClickFake Interview #ClickFix #cryptocurrency #Famous Chollima #GolangGhost #North Korea #Nuitka #PylangGhost #rat #social engineering #SOCRadar
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 28 Jul 2026 06:11:37 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ClickFake Interview #ClickFix #cryptocurrency #Famous Chollima #GolangGhost #North Korea #Nuitka #PylangGhost #rat #social engineering #SOCRadar
Daily CyberSecurity
Fake Job Interviews Deliver PylangGhost and GolangGhost RATs to Crypto Workers
At a glance Threat actor Famous Chollima, also called Wagemole; North Korea-aligned Activity type Social engineering via fake job interviews; ClickFix lures delivering RATs Targets Crypto and Web3…
⤷ Title: Insikt Group Finds Four New Golden Chickens Malware Families
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 28 Jul 2026 08:01:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ChonkyChicken #ChromEggscalator #ClickFix #Golden Chickens #Insikt Group #Malware_as_a_Service #TAG_195 #TinyEgg #Venom Spider
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 28 Jul 2026 08:01:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ChonkyChicken #ChromEggscalator #ClickFix #Golden Chickens #Insikt Group #Malware_as_a_Service #TAG_195 #TinyEgg #Venom Spider
Daily CyberSecurity
Insikt Group Finds Four New Golden Chickens Malware Families
At a glance Actor or group TAG-195, also tracked as Golden Chickens and Venom Spider; deployment observed by an operator tracked as TAG-127 Activity type Malware-as-a-service development; credenti…
⤷ Title: BlueNoroff Phishing Kit Turns Fake Zoom and Teams Calls Into a Crypto Wallet Theft Machine
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 30 Jul 2026 06:39:54 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BlueNoroff #ClickFix #Crypto theft #DPRK #JUMPSEC #Lazarus Group #NukeSped #Phishing Kit
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 30 Jul 2026 06:39:54 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BlueNoroff #ClickFix #Crypto theft #DPRK #JUMPSEC #Lazarus Group #NukeSped #Phishing Kit
Daily CyberSecurity
BlueNoroff Phishing Kit Turns Fake Zoom and Teams Calls Into a Crypto Wallet Theft Machine
At a glance Field Detail Actor / group BlueNoroff (TA444), a subgroup of North Korea’s Lazarus Group Activity type ClickFix phishing kit faking Zoom and Teams meetings Targets Web3 and crypt…
⤷ Title: CastleLoader Malware Now Delivers NeedleStealer Wallet and Browser Spoofers
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 06:11:48 +0000
════════════════════════
⌗ Tags: #Malware #Arctic Wolf #CastleLoader #CASTLESTEALER #ClickFix #crypto wallet spoofer #Infostealer #malware loader #NeedleStealer #NetSupport RAT
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 06:11:48 +0000
════════════════════════
⌗ Tags: #Malware #Arctic Wolf #CastleLoader #CASTLESTEALER #ClickFix #crypto wallet spoofer #Infostealer #malware loader #NeedleStealer #NetSupport RAT
Daily CyberSecurity
CastleLoader Malware Now Delivers NeedleStealer Wallet and Browser Spoofers
At a glance Malware family CastleLoader (loader); payloads include CastleStealer, NetSupport RAT, Lobshot, and NeedleStealer Threat actor Not named in this report; the loader is publicly tied to a…
⤷ Title: macOS ClickFix EtherHiding: DPRK Backdoor Hides C2 in Ethereum Smart Contracts
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 13:11:00 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #Contagious Interview #Crypto_Stealer #DPRK #EtherHiding #macOS Malware #Node.js Backdoor #UNC5342
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 13:11:00 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #Contagious Interview #Crypto_Stealer #DPRK #EtherHiding #macOS Malware #Node.js Backdoor #UNC5342
Information Security News
macOS ClickFix EtherHiding: DPRK Backdoor Hides C2 in Ethereum Smart Contracts
A routine internet search can culminate in a full macOS compromise – one in which a counterfeit system update prompt manipulates the user into executing a malicious command themselves, and t…
⤷ Title: Interlock Ransomware Abuses Volatility3 for Credential Theft
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 07:20:55 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #GOLD EMBRACE #Interlock ransomware #living off the land #Sophos #Volatility3
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 07:20:55 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #GOLD EMBRACE #Interlock ransomware #living off the land #Sophos #Volatility3
Daily CyberSecurity
Interlock Ransomware Abuses Volatility3 for Credential Theft
At a Glance Attribute Detail Malware family Interlock ransomware (double extortion) Threat actor Interlock, tracked by Sophos as GOLD EMBRACE (confirmed) Target / victims Critical infrastructure, …
⤷ Title: Fake AI Tools Malware Targets Developers Through GitHub
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 11 Aug 2026 07:42:05 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #EtherHiding #Infostealer #MaaS #Netskope #Polygon #SmartLoader
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 11 Aug 2026 07:42:05 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #EtherHiding #Infostealer #MaaS #Netskope #Polygon #SmartLoader
Daily CyberSecurity
Fake AI Tools Malware Targets Developers Through GitHub
At a glance Malware family MaaS infostealer delivered via SmartLoader (NodeJS strain among final payloads) Threat actor Operators behind TroyDen’s “lure factory” (suspected, not …
⤷ Title: DOUBLECUP: New ClickFix Loader Drops CountLoader and DeviceManager RAT
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 11 Aug 2026 06:42:07 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #CountLoader #DeviceManager RAT #DOUBLECUP #EtherHiding #Loader_as_a_Service
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 11 Aug 2026 06:42:07 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #CountLoader #DeviceManager RAT #DOUBLECUP #EtherHiding #Loader_as_a_Service
Daily CyberSecurity
DOUBLECUP: New ClickFix Loader Drops CountLoader and DeviceManager RAT
At a Glance Attribute Detail Malware family DOUBLECUP (Loader-as-a-Service); payloads CountLoader 4.5p and DeviceManager RAT Threat actor Rognar, a Russian operator (confirmed by SOCRadar) Target …
⤷ Title: macOS ClickFix Campaign Hides Its Lure Behind a Fingerprinting Gate
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 12 Aug 2026 07:30:46 +0000
════════════════════════
⌗ Tags: #Malware #AMOS #Atomic Stealer #ClickFix #Infostealer #macOS #MacSync #TDS
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 12 Aug 2026 07:30:46 +0000
════════════════════════
⌗ Tags: #Malware #AMOS #Atomic Stealer #ClickFix #Infostealer #macOS #MacSync #TDS
Daily CyberSecurity
macOS ClickFix Campaign Hides Its Lure Behind a Fingerprinting Gate
At a glance Malware family Atomic Stealer (AMOS) and MacSync infostealers Threat actor Unnamed operator running a Traffic Distribution System (attribution not stated) Target or victims Genuine mac…