logo

Australia warns of ClickFix attacks pushing Vidar Stealer malware

ID: 594db676-1353-51e3-b071-39c1709414d5

STIX ID: report--594db676-1353-51e3-b071-39c1709414d5

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Bill Toulas

...
...

The Australian Cyber Security Center warns of an active campaign using ClickFix social engineering on compromised WordPress sites to trick users into running PowerShell commands that install the Vidar Stealer info‑stealer; the advisory describes Vidar’s data theft capabilities, its memory-resident and anti-forensic behavior, use of public dead‑drop C2s, observed targeting of Australian organizations, and provides IoCs and mitigation recommendations (restrict PowerShell, application allow-listing, update/remove WordPress plugins/themes).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.