Qakbot Resurfaces in Fresh Wave of ClickFix Attacks
ID: 13d5af33-1003-54da-94de-e0c3d26fac8b
STIX ID: report--13d5af33-1003-54da-94de-e0c3d26fac8b
Feed Name: Dark Reading
Date Published: 2025-03-31
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Buguard researchers observed a cross‑border campaign (late 2024–early 2025) using fake CAPTCHA pages (the ClickFix technique) posted on LinkedIn and other social media to trick victims into pasting PowerShell commands; those flows lead to PHP droppers that download and execute Qakbot and other payloads (infostealers, ransomware). The activity affected multiple industries and countries, and some malicious domains (e.g., duolingos.com, cfcaptcha.com) hosting the dropper were removed as part of mitigation efforts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
