logo

ClickFix Alert: Fake Venture Capitalists Target Web3 Pros with “Terminal” Phishing

ID: 11ddf54f-21bc-5ba7-ac35-4d72f6bd55d8

STIX ID: report--11ddf54f-21bc-5ba7-ac35-4d72f6bd55d8

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-04

Date Updated: 2026-04-23

Author: Ddos

...
...

Moonlock Lab uncovered a coordinated campaign targeting crypto and Web3 professionals that uses fabricated VC personas and fake meeting links to redirect victims to a malicious page that employs a Cloudflare-branded fake CAPTCHA and clipboard poisoning ('ClickFix'). Victims are guided to paste clipboard commands into a terminal, enabling cross-platform execution—PowerShell in-memory loaders on Windows and macOS bash one-liners that can install Homebrew and deploy a Python-based payload—with behavioral overlaps to DPRK-aligned UNC1069 but no definitive attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.