hacker-news · Crawled Sep 24, 2026

17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360

5 IoCs
Read original article ↗

AI Summary

ClickFix is a social engineering-based initial access technique that manipulates users into pasting malicious commands into trusted system interfaces, bypassing traditional security controls. The attack leverages compromised websites, often WordPress-based, to serve fake verification pages that trigger clipboard manipulation and user-driven command execution. Infrastructure is resilient, using blockchain (Polygon) and Telegram/Steam for dynamic domain resolution, enabling rapid rotation and evasion of blocklists. Payloads are fingerprint-gated, delivering malware like Vidar Stealer only to specific victims based on hardware and account identifiers, making sandbox analysis unreliable.

AI-extracted · verify before operational use

Indicators of Compromise 5 extracted

Type Value Detail
GitHub Repo Sekoia/ErrTraffic Details →
Domain ctm360[.]com Details →
Domain polygon[.]com Details →
Domain telegram[.]org Details →
Domain store[.]steampowered[.]com Details →