ClickFix Campaign Exploits Fake LinkedIn VCs to Spread Malware Among Crypto and Web3 Experts
ID: f8b2c425-70e4-5dcc-9192-ab9db18b053d
STIX ID: report--f8b2c425-70e4-5dcc-9192-ab9db18b053d
Feed Name: GBHackers
Moonlock Lab reports a coordinated social-engineering and malware campaign targeting crypto and Web3 professionals through fake VC LinkedIn personas and spoofed meeting links; victims are lured into executing clipboard-poisoned commands via a fake Cloudflare-like CAPTCHA (ClickFix), enabling fileless PowerShell and multi-stage macOS payloads from attacker-controlled C2 domains. The write-up includes domains and URLs as IOCs, describes cross-platform tooling and credential exfiltration techniques, and notes operational similarities to UNC1069 while stopping short of definitive attribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
