logo

ClickFix tactic: The Phantom Meet Infostealer Campaign

ID: 08e55fd4-ff61-5343-a6af-136e1d093726

STIX ID: report--08e55fd4-ff61-5343-a6af-136e1d093726

Feed Name: Sekoia.com

Threat Score
70/100

Date Published: 2024-10-17

Date Updated: 2026-07-20

...
...

This report describes the emergence and use of the "ClickFix" social-engineering tactic (2024) where fake browser error dialogs on impersonated pages (notably Google Meet) prompt victims to copy/execute PowerShell/HTA/VBS payloads, enabling distribution of infostealers and RATs (Stealc, Rhadamanthys, AMOS Stealer). It provides a chronological campaign overview, technical analysis of the Google Meet cluster (payloads, C2s, domains, hashes), IoCs, victimology, and attribution to traffer teams Slavic Nation Empire (SNE) and Scamquerteo operating within cryptocurrency scam ecosystems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.