MalwareClickFix Turns Legitimate Websites and System Tools Into a Malware Delivery Chain
ClickFix tricks users into running malicious commands via fake Cloudflare checks, using 17,000+ infected sites, blockchain redirects and OS-specific lures.

Malware and threat intelligence
Matteo Riva is the AI profile for malware, ransomware and threat actors. It reconstructs documented attack chains and detection and mitigation opportunities. It separates malware families, operators and campaigns, attributing actor identifications and confidence to their sources. It does not invent indicators or present criminal claims as independently verified facts.
Listed sources guide priorities; they are neither exclusive nor evidence of a partnership. Each article identifies the sources actually used.
Profiles guide research and writing within the existing pipeline. Editorial checks, translation and publishing follow the shared CyberWorldOps rules.
The editorial operator evaluates corrections and may update profile rules. The system does not autonomously learn from its own articles.
New articles record the profile used during writing. Earlier coverage is grouped by topic and does not imply that these profiles produced historical articles. Only reporting published in this language is listed.
MalwareClickFix tricks users into running malicious commands via fake Cloudflare checks, using 17,000+ infected sites, blockchain redirects and OS-specific lures.
RansomwareRyuk member Karen Vardanyan sentenced to 2 years in U.S. for 2,400 ransomware attacks collecting $15M from hospitals, firms.
MalwareRemControl Android malware spreads via fake TVTap IPTV pages, stealing banking credentials with overlays, surveillance and remote control.
APTChinese-linked actor exploited WordPress, Zyxel and UniFi flaws to breach government networks, stealing 18,566 records and compromising 996 devices.
APTNorth Korea's Contagious Interview used fake coding tests to compromise 30,000 devices and 7,000 crypto wallets, causing $10.71M in losses.
MalwareChainScript RAT spreads through fake software installers, uses Node.js and PowerShell, and finds replaceable C2 servers through Polygon smart contracts.
APTJade Sleet breached an Indian IT firm via fake Terraform job tests, deploying FLATROOF and ROOFDECK macOS backdoors to steal credentials.
MalwareFBI seized NightmareStresser domains in Operation PowerOFF, disrupting a DDoS-for-hire service linked to hundreds of thousands of attacks.
MalwareKREMLIN malware installs rogue Chrome and Edge extensions by rewriting Chromium trust data to steal Brazilian banking credentials and session tokens.
MalwareA malicious npm campaign hides its payload in normal library functions, bypassing install-script controls and using runtime triggers, reconnaissance, and blockchain C2.
MalwareGoogle infiltrated TeamPCP’s inner chat to disrupt a supply-chain campaign, revoke stolen credentials, warn victims and uncover an AI-assisted zero-day exploit.
APTHEAVYGRAM uses Telegram bots to control Windows systems, steal credentials, capture data, evade Defender, and deploy further malware.