ClickFix tactic: The Phantom Meet (Infostealers)
ID: c3f4246c-3392-5904-867d-ac7f5a00000f
STIX ID: report--c3f4246c-3392-5904-867d-ac7f5a00000f
Feed Name: infostealers.com
**Executive summary:** Sekoia.io documents an emerging 2024 social‑engineering tactic dubbed ClickFix that displays fake browser error dialogs (including fake Google Meet pages) to coerce victims into copying PowerShell/HTA commands or downloading payloads; the cluster analyzed distributes Windows and macOS infostealers (Stealc, Rhadamanthys, AMOS), exposes numerous IoCs and C2 servers, and is attributed to traffer subgroups (Slavic Nation Empire and Scamquerteo) within the cryptocurrency scam ecosystem.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
