ClickFix Alert: Fake Venture Capitalists Target Web3 Pros with “Terminal” Phishing
ID: 11ddf54f-21bc-5ba7-ac35-4d72f6bd55d8
STIX ID: report--11ddf54f-21bc-5ba7-ac35-4d72f6bd55d8
Feed Name: securityonline.info
Moonlock Lab uncovered a coordinated campaign targeting crypto and Web3 professionals that uses fabricated VC personas and fake meeting links to redirect victims to a malicious page that employs a Cloudflare-branded fake CAPTCHA and clipboard poisoning ('ClickFix'). Victims are guided to paste clipboard commands into a terminal, enabling cross-platform execution—PowerShell in-memory loaders on Windows and macOS bash one-liners that can install Homebrew and deploy a Python-based payload—with behavioral overlaps to DPRK-aligned UNC1069 but no definitive attribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
