logo

Qakbot Resurfaces in Fresh Wave of ClickFix Attacks

ID: 13d5af33-1003-54da-94de-e0c3d26fac8b

STIX ID: report--13d5af33-1003-54da-94de-e0c3d26fac8b

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-03-31

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Buguard researchers observed a cross‑border campaign (late 2024–early 2025) using fake CAPTCHA pages (the ClickFix technique) posted on LinkedIn and other social media to trick victims into pasting PowerShell commands; those flows lead to PHP droppers that download and execute Qakbot and other payloads (infostealers, ransomware). The activity affected multiple industries and countries, and some malicious domains (e.g., duolingos.com, cfcaptcha.com) hosting the dropper were removed as part of mitigation efforts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.