Threat Actors Push ClickFix Fake Browser Updates Using Stolen Credentials
ID: 7db7e6cd-2589-5895-85b0-2cb990d961fd
STIX ID: report--7db7e6cd-2589-5895-85b0-2cb990d961fd
Feed Name: infostealers.com
GoDaddy Security describes an active campaign where attackers install large numbers of bogus WordPress plugins (using stolen admin credentials) to inject ClickFix/ClearFake fake-browser-update JavaScript that uses blockchain smart contracts (EtherHiding) to retrieve and serve malware payloads (notably info-stealers such as Vidar and Lumma); the report provides IoCs (plugin paths, MD5/SHA256 hashes, smart contract IDs, endpoints, GitHub/BitBucket accounts) and attack-log evidence showing automated credential-based compromise across thousands of sites.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
