logo

ClickFix Campaign Uses Fake VCs on LinkedIn to Deliver Malware to Crypto and Web3 Professionals

ID: 418eb88f-70aa-5dde-a2ac-c0065579ae95

STIX ID: report--418eb88f-70aa-5dde-a2ac-c0065579ae95

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-05

Date Updated: 2026-05-05

Author: Tushar Subhra Dutta

...
...

Moonlock describes an active, targeted campaign that uses LinkedIn personas and spoofed conferencing pages to coerce crypto/Web3 professionals into executing clipboard-pasted commands (ClickFix), delivering stealthy cross-platform malware (in-memory PowerShell on Windows; Homebrew/Python-based installers on macOS); researchers mapped domains, registrant details, and analyzed Mach-O binaries, and observed patterns resembling UNC1069.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.