logo

ClickFix distributing Vidar Stealer via WordPress targeting Australian infrastructure

ID: 4010b46f-3a25-5c01-b0e8-c63d512e796b

STIX ID: report--4010b46f-3a25-5c01-b0e8-c63d512e796b

Feed Name: ASD's ACSC - Advisories RSS

Threat Score
70/100

Date Published: 2026-05-06

Date Updated: 2026-07-24

Author: Australian Cyber Security Centre (ACSC)

...
...

### Executive summary: The Australian Signals Directorate's ACSC reports an active ClickFix campaign using compromised WordPress sites to display fake verification prompts that copy obfuscated PowerShell commands to victims' clipboards; when executed, these commands download and run the Vidar Stealer infostealer to exfiltrate credentials, browser data and wallets. The advisory details observed TTPs (including PowerShell execution, user-driven copy/paste execution, file self-deletion, HTTP/S C2 via dead-drop resolvers), maps them to MITRE ATT&CK, provides IOCs and detection IDs, and recommends mitigations such as application control, patching, MFA, PowerShell restrictions, DLP and security awareness training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.