{
  "id": 6264766,
  "title": "ClickFix moves into the browser and onto WebDAV, Cisco Talos finds",
  "url": "https://urgent.news/2026/09/08/clickfix-moves-into-the-browser-and-onto-webdav-cisco-talos-finds",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-08T10:00:04.000Z",
  "source": {
    "name": "SiliconANGLE",
    "slug": "siliconangle",
    "url": "https://siliconangle.com/2026/09/08/clickfix-moves-into-the-browser-and-onto-webdav-cisco-talos-finds/"
  },
  "original_language": "en",
  "account": "Two ClickFix campaigns were explored by Cisco Systems Inc.'s Talos Threat Intelligence group, extending the malware's reach beyond the traditional copy-and-paste PowerShell prompt. One campaign operated without touching the operating system, while the other culminated in a stealer and a follow-on payload chosen by the operators. ClickFix gained prominence in 2024, operating by presenting a page claiming a failure and offering a command to paste into the Windows Run dialog or a Mac terminal. This method bypasses warning warnings and email filtering that typically catch attachments. The malware spread rapidly, being found in a fake OpenAI Codex installer for Mac users, as documented by Cato Networks Ltd. In the first campaign, the target remained Windows-free. The lure involved pasting JavaScript into the Chrome address bar or installing it into the Tampermonkey browser extension, which reloads the code on every visit to the targeted site. The code skimmed by hooking the browser's fetch application programming interface, replacing cryptocurrency deposit addresses in server responses and the clipboard, and creating counterfeit \"bonus\" elements to account for the numbers seen by the victim. Talos observed this campaign against SwapZone.io and later SimpleSwap.io, using Google Visualization API and Google Docs as command and control channels. The operators hid obfuscated payload code in a Google Sheet and accessed it via a query embedded in a URL. The campaign involved 49 bitcoin addresses, with 30 repeating across most samples, resulting in transactions totaling approximately $10,000. The operators moved quickly, reappearing after takedowns, and even placed the first-stage script in Google Docs after paste.sh began detecting it. The second campaign initiated through a compromised website using a malicious Cloudflare Worker to inject ClearFake JavaScript, stored in a BNB Smart Chain smart contract. On Windows, it presented a fake Google CAPTCHA and executed a disguised DLL through rundll32 by function ordinal. Talos identified the actor behind the attacks as UAT-10820, tracking their \"verification.google\" activity. Both loaders delivered Amatera, an infostealer with a configuration covering various browsers, extensions, messaging apps, password managers, desktop wallet locations, authenticator apps, and VPN clients.",
  "summary": "Cisco Systems Inc.’s Talos Threat Intelligence group today detailed two ClickFix campaigns that push the technique past the copy-and-paste PowerShell prompt it is known for, one that never touches the operating system at all and one that ends in a stealer plus whichever follow-on payload the operators choose to task. ClickFix emerged in 2024 and […] The post ClickFix moves into the browser and…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}