⤷ Title: Reaper macOS Infostealer Abuses Script Editor to Steal Crypto and Passwords
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Fri, 05 Jun 2026 13:06:01 +0000
════════════════════════
⌗ Tags: #Security #Malware #ClickFix #Crypto #Infostealer #macOS #Password #Reaper #Script Editor #SHub Stealer #WeChat
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Fri, 05 Jun 2026 13:06:01 +0000
════════════════════════
⌗ Tags: #Security #Malware #ClickFix #Crypto #Infostealer #macOS #Password #Reaper #Script Editor #SHub Stealer #WeChat
Hackread
Reaper macOS Infostealer Abuses Script Editor to Steal Crypto and Passwords
Threat actors deploy Reaper, an updated SHub Stealer variant abusing macOS Script Editor to bypass protections and steal cryptocurrency assets.
⤷ Title: ClickFix Malware Hijacks Fake Amazon Alert to Drop HarborWatch Agent
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Jun 2026 15:41:58 +0000
════════════════════════
⌗ Tags: #Malware #Amazon Phishing #ClickFix #Cofense #HarborWatch Agent #RAT #Social Engineering
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Jun 2026 15:41:58 +0000
════════════════════════
⌗ Tags: #Malware #Amazon Phishing #ClickFix #Cofense #HarborWatch Agent #RAT #Social Engineering
Information Security News
ClickFix Malware Drops HarborWatch Agent RAT
A fake Amazon alert uses ClickFix malware to trick users into deploying the HarborWatch Agent RAT. See how the self-infection scam works.
⤷ Title: SilabRAT Malware: The $5,000-a-Month Crypto-Hunting RAT Hiding Behind HijackLoader
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 07:22:05 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #cryptocurrency #Group_IB #HijackLoader #HVNC #Malware_as_a_Service #rat #SilabRAT #SnappyClient
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 07:22:05 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #cryptocurrency #Group_IB #HijackLoader #HVNC #Malware_as_a_Service #rat #SilabRAT #SnappyClient
Daily CyberSecurity
SilabRAT Malware: The $5,000-a-Month Crypto-Hunting RAT Hiding Behind HijackLoader
SilabRAT malware, aka SnappyClient, is a $5K/month MaaS RAT flagged as HijackLoader. It uses HVNC and cracks crypto wallets, per Group-IB.
⤷ Title: ErrTraffic Malware Spreads ClickFix Lures via Hacked WordPress Sites
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 22 Jun 2026 01:26:58 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #CVE_2020_25213 #ErrTraffic #EtherHiding #Malware_as_a_Service #TDS #Vidar #wordpress
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 22 Jun 2026 01:26:58 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #CVE_2020_25213 #ErrTraffic #EtherHiding #Malware_as_a_Service #TDS #Vidar #wordpress
Daily CyberSecurity
ErrTraffic Malware Spreads ClickFix Lures via Hacked WordPress Sites
ErrTraffic malware powers ClickFix attacks on hacked WordPress sites, using EtherHiding on the blockchain to hide its C2 and spread infostealers.
⤷ Title: macOS ClickFix AppleScript Stealer Hijacks Crypto Wallets
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 23 Jun 2026 08:28:10 +0000
════════════════════════
⌗ Tags: #Malware #AppleScript Stealer #ClickFix #CVE_2024_27804 #CVE_2024_27805 #CVE_2024_27806 #macOS
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 23 Jun 2026 08:28:10 +0000
════════════════════════
⌗ Tags: #Malware #AppleScript Stealer #ClickFix #CVE_2024_27804 #CVE_2024_27805 #CVE_2024_27806 #macOS
Daily CyberSecurity
macOS ClickFix AppleScript Stealer Hijacks Crypto Wallets
A new macOS ClickFix AppleScript stealer named the Meow macOS stealer acts as a persistent RAT, hijacking wallets and evading detection. Protect your Macs.
⤷ Title: SmartApeSG Hijacks Okendo Reviews Widget in Supply Chain Attack
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 24 Jun 2026 03:26:12 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #Okendo Reviews #SmartApeSG #StealC #supply chain attack #Zscaler
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 24 Jun 2026 03:26:12 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #Okendo Reviews #SmartApeSG #StealC #supply chain attack #Zscaler
Information Security News
SmartApeSG Hijacks Okendo Reviews Widget in Supply Chain Attack
Attackers injected malicious JavaScript into Okendo Reviews, a product review widget used by more than 18,000 brands. The compromised script loaded on store pages. After a few checks, it could sho…
⤷ Title: SmartRAT ClickFix Campaign Identified
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 24 Jun 2026 07:26:33 +0000
════════════════════════
⌗ Tags: #Malware #Banana RAT #ClickFix Campaign #CVE_2026_25089 #CVE_2026_26980 #CVE_2026_39808 #SmartRAT
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 24 Jun 2026 07:26:33 +0000
════════════════════════
⌗ Tags: #Malware #Banana RAT #ClickFix Campaign #CVE_2026_25089 #CVE_2026_26980 #CVE_2026_39808 #SmartRAT
Daily CyberSecurity
SmartRAT ClickFix Campaign Identified
An AI-generated SmartRAT ClickFix campaign targets banking users, mimicking the Banana RAT. This threat relates to flaws like CVE-2026-26980.
⤷ Title: Hackers Abused Claude.ai Shared Chat in a ClickFix Malvertising Campaign
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 24 Jun 2026 06:20:09 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Claude AI #ClickFix #Google Ads #Infostealer #MacSync #Malvertising
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 24 Jun 2026 06:20:09 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Claude AI #ClickFix #Google Ads #Infostealer #MacSync #Malvertising
Daily CyberSecurity
Hackers Abused Claude.ai Shared Chat in a ClickFix Malvertising Campaign
Trend Micro tracked a ClickFix malvertising campaign that abused claude.ai shared chat to deliver the MacSync infostealer to Mac developers.
⤷ Title: ClickFix Scams Abuse Google, Cloudflare Checks to Deliver 7 Malware Families
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 12:39:37 +0000
════════════════════════
⌗ Tags: #Security #Malware #Scams and Fraud #ClickFix #CloudFlare #Cyber Attack #Cybersecurity #Google
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 12:39:37 +0000
════════════════════════
⌗ Tags: #Security #Malware #Scams and Fraud #ClickFix #CloudFlare #Cyber Attack #Cybersecurity #Google
Hackread
ClickFix Scam Abuses Google, Cloudflare Checks to Deliver 7 Malware Families
Malwarebytes links fake Google and Cloudflare verification pages to shared ClickFix infrastructure delivering StealC, NetSupport and other malware.
⤷ Title: uBlock Origin Blocks ClickFix Malware Pop-ups
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 09:51:57 +0000
════════════════════════
⌗ Tags: #Malware #ad blocker #BNB Chain #browser security #ClickFix #Malware Protection #Social Engineering #UBlock Origin
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 09:51:57 +0000
════════════════════════
⌗ Tags: #Malware #ad blocker #BNB Chain #browser security #ClickFix #Malware Protection #Social Engineering #UBlock Origin
Information Security News
uBlock Origin Blocks ClickFix Malware Pop-ups
uBlock Origin, the popular ad-blocking extension, has gained new capabilities to protect users. It now detects and blocks websites that display malicious ClickFix pop-ups. These sites try to trick…
⤷ Title: Mexican Banking Fraud: REF6045 Operation Exposed
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 14 Jul 2026 06:15:56 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Banking Fraud #ClickFix #malware #REF6045 #SCMBANKER
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 14 Jul 2026 06:15:56 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Banking Fraud #ClickFix #malware #REF6045 #SCMBANKER
Daily CyberSecurity
Mexican Banking Fraud: REF6045 Operation Exposed
On June 18, 2026, security analysts detected a host downloading suspicious PowerShell scripts from an open directory. At a glance Actor or Group: REF6045 (suspected) Activity Type: Phishing, vishi…
⤷ Title: TELEPUZ: A New Modular MaaS Malware Spreads Through ClickFix Lures on Compromised Websites
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 12:00:08 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #Elastic Security Labs #MaaS #TELEPUZ #Vidar
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 12:00:08 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #Elastic Security Labs #MaaS #TELEPUZ #Vidar
Information Security News
TELEPUZ: A New Modular MaaS Malware Spreads Through ClickFix Lures on Compromised Websites
Since late April 2026, compromised websites have been distributing a new modular malware with the curious name “TELEPUZ” through the ClickFix scheme. According to Elastic, the attacker…
⤷ Title: ClickLock Stealer Locks macOS Screens Until Victims Hand Over Their Password
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 06:26:00 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #ClickLock Stealer #crypto wallet #Group_IB #GSocket #Infostealer #macOS Malware #Telegram C2
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 06:26:00 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #ClickLock Stealer #crypto wallet #Group_IB #GSocket #Infostealer #macOS Malware #Telegram C2
Daily CyberSecurity
ClickLock Stealer Locks macOS Screens Until Victims Hand Over Their Password
At a glance Malware family ClickLock Stealer (new, named by Group-IB) Threat actor Unattributed. No actor or group named. Target / victims macOS users, especially crypto holders. At least 100 vict…
⤷ Title: TELEPUZ Malware Spreads Through ClickFix and VIDAR Attacks
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 14:57:42 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #Elastic Security Labs #Infostealer #MaaS #TELEPUZ #Vidar #WebInject
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 14:57:42 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #Elastic Security Labs #Infostealer #MaaS #TELEPUZ #Vidar #WebInject
Daily CyberSecurity
TELEPUZ Malware Spreads Through ClickFix and VIDAR Attacks
At a glance Malware family TELEPUZ Threat actor Unnamed; suspected solo developer or small team running a MaaS Target / victims Windows users reached through compromised web pages Delivery vector …
⤷ Title: Starland RAT Campaign by Russian-Speaking Actor UAT-11795 Targets Crypto Users in the US and Europe
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 22 Jul 2026 13:58:09 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CASTLESTEALER #Cisco Talos #ClickFix #Cryptocurrency Theft #Remcos RAT #Starland RAT #Telegram C2 #UAT_11795 #WLDR Agent
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 22 Jul 2026 13:58:09 +0000
════════════════════════
⌗ Tags: #Cybercriminals #CASTLESTEALER #Cisco Talos #ClickFix #Cryptocurrency Theft #Remcos RAT #Starland RAT #Telegram C2 #UAT_11795 #WLDR Agent
Daily CyberSecurity
Starland RAT Campaign by Russian-Speaking Actor UAT-11795 Targets Crypto Users in the US and Europe
At a glance Actor / group UAT-11795 (suspected Russian-speaking, financially motivated) Activity type Credential and cryptocurrency theft via trojanized software installers Targets / victims Windo…
⤷ Title: ACR Stealer Spreads Through ClickFix Lures in Two Attack Chains
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 06:40:20 +0000
════════════════════════
⌗ Tags: #Malware #ACR Stealer #ClickFix #Credential Theft #EtherHiding #Infostealer #Malware_as_a_Service #Microsoft Defender #powershell
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 06:40:20 +0000
════════════════════════
⌗ Tags: #Malware #ACR Stealer #ClickFix #Credential Theft #EtherHiding #Infostealer #Malware_as_a_Service #Microsoft Defender #powershell
Daily CyberSecurity
ACR Stealer Spreads Through ClickFix Lures in Two Attack Chains
At a glance Malware family ACR Stealer (infostealer; linked to a rebrand of Amatera Stealer) Threat actor No named actor; sold via malware-as-a-service (MaaS) Target / victims Enterprise Windows e…
⤷ Title: TAG-150 Attack Chain Deploys DenoRAT Malware
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 08:01:09 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #DenoRAT #malware #NightshadeC2 #TAG_150
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 08:01:09 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #DenoRAT #malware #NightshadeC2 #TAG_150
Daily CyberSecurity
TAG-150 Attack Chain Deploys DenoRAT Malware
A recent cyberattack targeted a financial institution using a ClickFix social engineering lure. This incident revealed an evolving TAG-150 attack chain. Security researchers from eSentire Threat R…
⤷ Title: TAG-195 Deploys ChonkyChicken Modular Malware Framework
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Sun, 26 Jul 2026 14:45:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ChonkyChicken #ClickFix #Malware_as_a_Service #TAG_195 #TinyEgg
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Sun, 26 Jul 2026 14:45:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ChonkyChicken #ClickFix #Malware_as_a_Service #TAG_195 #TinyEgg
Information Security News
TAG-195 Deploys ChonkyChicken Modular Malware Framework
Evolution of the Golden Chickens Ecosystem Cybercriminals operating within the TAG-195 ecosystem have fundamentally restructured their malware architecture, adopting a highly modular approach. Con…
⤷ Title: Fake Job Interviews Deliver PylangGhost and GolangGhost RATs to Crypto Workers
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 28 Jul 2026 06:11:37 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ClickFake Interview #ClickFix #cryptocurrency #Famous Chollima #GolangGhost #North Korea #Nuitka #PylangGhost #rat #social engineering #SOCRadar
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 28 Jul 2026 06:11:37 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ClickFake Interview #ClickFix #cryptocurrency #Famous Chollima #GolangGhost #North Korea #Nuitka #PylangGhost #rat #social engineering #SOCRadar
Daily CyberSecurity
Fake Job Interviews Deliver PylangGhost and GolangGhost RATs to Crypto Workers
At a glance Threat actor Famous Chollima, also called Wagemole; North Korea-aligned Activity type Social engineering via fake job interviews; ClickFix lures delivering RATs Targets Crypto and Web3…
⤷ Title: Insikt Group Finds Four New Golden Chickens Malware Families
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 28 Jul 2026 08:01:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ChonkyChicken #ChromEggscalator #ClickFix #Golden Chickens #Insikt Group #Malware_as_a_Service #TAG_195 #TinyEgg #Venom Spider
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 28 Jul 2026 08:01:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ChonkyChicken #ChromEggscalator #ClickFix #Golden Chickens #Insikt Group #Malware_as_a_Service #TAG_195 #TinyEgg #Venom Spider
Daily CyberSecurity
Insikt Group Finds Four New Golden Chickens Malware Families
At a glance Actor or group TAG-195, also tracked as Golden Chickens and Venom Spider; deployment observed by an operator tracked as TAG-127 Activity type Malware-as-a-service development; credenti…