A North Korean hacking group expands its macOS attacks with a new ClickFix tactic that leads to malware installation through fake system crash notifications and uses blockchain to obscure command and control servers.
Cybercriminals exploit legitimate AI chat sharing features from Claude to trick developers into manually executing malware and stealing corporate login credentials.
ACR Stealer employs two technically distinct campaigns to circumvent security tools and fragment investigations without exploiting software vulnerabilities.
ACR Stealer infects enterprise customers through fake error messages with manipulated commands and steals browser data, credentials, and cloud content.
ACR Stealer exfiltrates browser credentials and Microsoft 365 content from enterprise environments via ClickFix lures by manipulating users to execute PowerShell commands directly.
A new ClickFix campaign automates malware downloads on macOS entirely through terminal commands, with Atomic macOS Stealer stealing passwords, browser data, and cryptocurrency wallet holdings.
Three new malware loaders (BabaDeda, Lorem Ipsum, Potemkin) distribute via ClickFix social engineering and compromised WordPress sites to enable data theft, ransomware, and remote control.