Skip to content

Campaign index

Every ClickFix campaign on record

One operation as the people who documented it described it, reconciled across vendors into a single record.

44 published records · page 1 of 3

Published campaign records

  • Published 2026-08-29Status as last assessed: Active

    StopAndProtect ClickFix operation

    Reported by Check Point Research

    Targets Windows

    Indicators
    39
    First seen
    2026-04-24
  • Published 2026-08-29Status as last assessed: Active

    SHub and MacSync via GitHub lures

    Reported by Datadog Security Labs

    Targets macOS

    Indicators
    26
    First seen
  • Published 2026-08-29Status as last assessed: Active

    ModeloRAT via a fake CrashFix popup

    Reported by Microsoft Threat Intelligence

    Targets Windows

    Indicators
    20
    First seen
  • Published 2026-08-15Status as last assessed: Active

    MIMICRAT via compromised websites

    Reported by Stormshield Customer Security Lab, Elastic Security Labs

    Targets Windows

    Indicators
    193
    First seen
    2026-02-11
  • Published 2026-08-07Status as last assessed: Active

    Latrodectus and Supper in Poland

    Reported by CERT Polska

    Targets Windows

    Indicators
    15
    First seen
  • Published 2026-08-07Status as last assessed: Active

    Interlock ransomware and FileFix

    Reported by The DFIR Report, CISA

    Targets Windows

    Indicators
    50
    First seen
    2024-09-01
  • Published 2026-08-07Status as last assessed: Active

    Rhadamanthys in a fake update lure

    Reported by Huntress

    Targets Windows

    Indicators
    21
    First seen
    2025-10-01
  • Published 2026-08-07Status as last assessed: Active

    Lumma Stealer's PNG stego loader

    Reported by Huntress

    Targets Windows

    Indicators
    19
    First seen
    2025-10-01
  • Published 2026-08-07Status as last assessed: Active

    ARECHCLIENT2 via GHOSTPULSE

    Reported by Elastic Security Labs

    Targets Windows

    Indicators
    56
    First seen
    2024-12-13
  • Published 2026-08-07Status as last assessed: Archived

    XFiles Stealer via early IClickFix

    Reported by Sekoia.io

    Targets Windows

    Indicators
    5
    First seen
    2024-12-18
  • Published 2026-08-07Status as last assessed: Active

    NetSupport RAT via IClickFix

    Reported by Sekoia.io

    Targets Windows

    Indicators
    111
    First seen
    2024-12-18
  • Published 2026-08-07Status as last assessed: Active

    Phantom Meet fake download sites

    Reported by Sekoia.io

    Targets Windows, macOS

    Indicators
    124
    First seen
  • Published 2026-08-07Status as last assessed: Active

    AMOS via a shared delivery layer

    Reported by Sekoia.io

    Targets macOS

    Indicators
    20
    First seen
    2024-05-01
  • Published 2026-08-07Status as last assessed: Active

    Google Meet clones, three stealers

    Reported by Sekoia.io

    Targets Windows, macOS

    Indicators
    34
    First seen
  • Published 2026-08-07Status as last assessed: Active

    AsyncRAT and XWorm on one host

    Reported by Trend Micro

    Targets Windows

    Indicators
    1
    First seen
  • Published 2026-08-07Status as last assessed: Active

    mshta lures fetching remote HTAs

    Reported by Trend Micro

    Targets Windows

    Indicators
    6
    First seen
  • Published 2026-08-07Status as last assessed: Active

    Hotel lost-property phishing mail

    Reported by Trend Micro

    Targets Windows

    Indicators
    7
    First seen
  • Published 2026-08-07Status as last assessed: Active

    Emmenhtal Loader inside an MP3

    Reported by Trend Micro

    Targets Windows

    Indicators
    11
    First seen
  • Published 2026-08-07Status as last assessed: Active

    Odyssey Stealer's shared codebase

    Reported by Unit 42, Palo Alto Networks

    Targets macOS, Windows

    Indicators
    51
    First seen
    2025-04-14
  • Published 2026-08-07Status as last assessed: Active

    DeerStealer via an IUAM kit page

    Reported by Unit 42, Palo Alto Networks

    Targets Windows

    Indicators
    24
    First seen