logo

ClickFix Campaign Exploits Fake LinkedIn VCs to Spread Malware Among Crypto and Web3 Experts

ID: f8b2c425-70e4-5dcc-9192-ab9db18b053d

STIX ID: report--f8b2c425-70e4-5dcc-9192-ab9db18b053d

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-05

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Moonlock Lab reports a coordinated social-engineering and malware campaign targeting crypto and Web3 professionals through fake VC LinkedIn personas and spoofed meeting links; victims are lured into executing clipboard-poisoned commands via a fake Cloudflare-like CAPTCHA (ClickFix), enabling fileless PowerShell and multi-stage macOS payloads from attacker-controlled C2 domains. The write-up includes domains and URLs as IOCs, describes cross-platform tooling and credential exfiltration techniques, and notes operational similarities to UNC1069 while stopping short of definitive attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.