TerminalFix is a new ClickFix campaign that tricks users into running PowerShell commands and turns infected Windows PCs into network pivots.
A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into ...
Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance.
PavinLoader uses fake CAPTCHAs, game installers, and software downloads to deliver malware and steal passwords, browser data, ...
SOCRadar details E4del and PINHOLE RAT campaigns using FTP banners as dead drop resolvers to fetch commands and C2 details.
An advanced malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with ...
WordlistLoader delivers Amatera via ClearFake ClickFix attacks, while SynkLoader uses Teams phishing to steal Windows login ...
We found PavinLoader being used across ClickFix, fake software, and RenPy campaigns to deliver Amatera Stealer and other ...
SynkLoader malware is spreading through Microsoft Teams phishing, using a fake Windows lock screen to steal credentials and enable remote access.
Cybersecurity researchers have identified an unusual malware campaign in which attackers are abusing FTP server banners to hide commands used to deliver two previously undocumented Windows remote ...
A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal ...
Microsoft released PowerShell scripts that let IT admins view, export, and delete Windows settings backup data through ...