Australian Cyber Security Centre Issues Alert Over ClickFix Attacks
ID: 0be6ac23-256b-578d-9ef2-a89aaa53e9b3
STIX ID: report--0be6ac23-256b-578d-9ef2-a89aaa53e9b3
Feed Name: Infosecurity Magazine (News)
The Australian Cyber Security Centre (ACSC) warns of a widespread campaign distributing the Vidar Stealer infostealer by using compromised WordPress sites and the ClickFix social-engineering technique (fake CAPTCHA prompts) to trick Windows users into executing malicious commands. Vidar steals credentials, payment data, crypto wallets and MFA tokens, uses in-memory persistence and self-deletion to evade detection, and the alert includes mitigation advice such as restricting unapproved execution, patching software, limiting clipboard writes, and enforcing phishing-resistant MFA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
