ThreatPaper

#clickfix

2 cases

Blackpoint APG documented ChainScript, a full-featured RAT pushed via ClickFix lures (fake Spotify/Zoom/Teams installers) that reads a Polygon smart contract to find its live WebSocket C2 — an EtherHiding-style design built to survive takedowns and defeat indicator-based blocking.

MalwareSocial EngineeringCryptocurrency & Web3

A hardcoded Cloudflare API key let attackers rewrite Brevo's web pages and the JavaScript widgets 100,000+ customer sites embed, serving a fake-CAPTCHA "ClickFix" clipboard-hijack lure and a password-bypassing WordPress backdoor for over five hours on September 14, 2026.

Supply Chain AttackMalwareSocial Engineering