logo

ClickFix tactic: The Phantom Meet (Infostealers)

ID: c3f4246c-3392-5904-867d-ac7f5a00000f

STIX ID: report--c3f4246c-3392-5904-867d-ac7f5a00000f

Feed Name: infostealers.com

Threat Score
75/100

Date Published: 2024-10-20

Date Updated: 2026-06-07

Author: InfoStealers

...
...

**Executive summary:** Sekoia.io documents an emerging 2024 social‑engineering tactic dubbed ClickFix that displays fake browser error dialogs (including fake Google Meet pages) to coerce victims into copying PowerShell/HTA commands or downloading payloads; the cluster analyzed distributes Windows and macOS infostealers (Stealc, Rhadamanthys, AMOS), exposes numerous IoCs and C2 servers, and is attributed to traffer subgroups (Slavic Nation Empire and Scamquerteo) within the cryptocurrency scam ecosystem.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.