logo

Threat Actors Push ClickFix Fake Browser Updates Using Stolen Credentials 

ID: 7db7e6cd-2589-5895-85b0-2cb990d961fd

STIX ID: report--7db7e6cd-2589-5895-85b0-2cb990d961fd

Feed Name: infostealers.com

Threat Score
78/100

Date Published: 2024-10-27

Date Updated: 2026-04-28

Author: InfoStealers

...
...

GoDaddy Security describes an active campaign where attackers install large numbers of bogus WordPress plugins (using stolen admin credentials) to inject ClickFix/ClearFake fake-browser-update JavaScript that uses blockchain smart contracts (EtherHiding) to retrieve and serve malware payloads (notably info-stealers such as Vidar and Lumma); the report provides IoCs (plugin paths, MD5/SHA256 hashes, smart contract IDs, endpoints, GitHub/BitBucket accounts) and attack-log evidence showing automated credential-based compromise across thousands of sites.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.