Skip to content

Campaign index

Every ClickFix campaign on record, page 2

A campaign is one operation as described by the people who documented it. This is page 2 of the index, ordered newest first. Start at the beginning for what each record contains and how it is built.

44 published records · page 2 of 3

  • Published 2026-08-07Status as last assessed: Active

    IUAM ClickFix Generator

    Reported by Unit 42, Palo Alto Networks

    Targets Cross-platform

    Indicators
    1
    First seen
    2025-07-18
  • Published 2026-08-07Status as last assessed: Dormant

    UNK_RemoteRogue using Empire

    Reported by Proofpoint

    Targets Windows

    Indicators
    5
    First seen
    2024-12-09
  • Published 2026-08-07Status as last assessed: Dormant

    MuddyWater deploying Level RMM

    Reported by Proofpoint

    Targets Windows

    Indicators
    2
    First seen
    2024-11-13
  • Published 2026-08-07Status as last assessed: Active

    Kimsuky deploying QuasarRAT

    Reported by Proofpoint

    Targets Windows

    Indicators
    52
    First seen
    2025-01-01
  • Published 2026-08-07Status as last assessed: Active

    UAC-0050 overlap in Ukrainian mail

    Reported by Proofpoint

    Targets Windows

    Indicators
    5
    First seen
    2024-10-31
  • Published 2026-08-07Status as last assessed: Active

    XWorm via ChatGPT malvertising

    Reported by Proofpoint

    Targets Windows

    Indicators
    4
    First seen
    2024-10-19
  • Published 2026-08-07Status as last assessed: Active

    Brute Ratel C4, then Latrodectus

    Reported by Proofpoint

    Targets Windows

    Indicators
    10
    First seen
    2024-09-20
  • Published 2026-08-07Status as last assessed: Active

    NetSupport RAT via link-free mail

    Reported by Proofpoint

    Targets Windows

    Indicators
    1
    First seen
    2024-09-05
  • Published 2026-08-07Status as last assessed: Active

    Ricardo marketplace lure in German

    Reported by Proofpoint

    Targets Windows

    Indicators
    6
    First seen
    2024-09-25
  • Published 2026-08-07Status as last assessed: Active

    AMOS with a hidden boot backdoor

    Reported by Microsoft Threat Intelligence

    Targets macOS

    Indicators
    43
    First seen
    2026-01-31
  • Published 2026-08-07Status as last assessed: Active

    Telegram fallback C2 on macOS

    Reported by Microsoft Threat Intelligence

    Targets macOS

    Indicators
    17
    First seen
    2026-04-01
  • Published 2026-08-07Status as last assessed: Active

    SHub Stealer via macOS Terminal

    Reported by Microsoft Threat Intelligence

    Targets macOS

    Indicators
    71
    First seen
    2026-02-01
  • Published 2026-08-07Status as last assessed: Active

    macOS disk-cleanup lure sites

    Reported by Microsoft Threat Intelligence

    Targets macOS

    Indicators
    15
    First seen
    2026-01-31
  • Published 2026-08-07Status as last assessed: Active

    AMOS behind a fingerprint gate

    Reported by Microsoft Threat Intelligence

    Targets macOS

    Indicators
    17
    First seen
  • Published 2026-08-07Status as last assessed: Active

    Cloudflare Turnstile iframe lure

    Reported by Microsoft Threat Intelligence

    Targets Windows

    Indicators
    1
    First seen
    2025-05-22
  • Published 2026-08-07Status as last assessed: Active

    AMOS via a fake Spectrum page

    Reported by Microsoft Threat Intelligence, CloudSEK

    Targets macOS, Windows

    Indicators
    12
    First seen
    2025-05-30
  • Published 2026-08-07Status as last assessed: Active

    OBSCURE#BAT via a Discord lure

    Reported by Microsoft Threat Intelligence, Securonix Threat Research

    Targets Windows

    Indicators
    179
    First seen
    2025-02-24
  • Published 2026-08-07Status as last assessed: Active

    Latrodectus from Storm-0249

    Reported by Microsoft Threat Intelligence

    Targets Windows

    Indicators
    1
    First seen
    2025-05-14
  • Published 2026-08-07Status as last assessed: Active

    Lumma Stealer via film piracy sites

    Reported by Microsoft Threat Intelligence

    Targets Windows

    Indicators
    1
    First seen
    2025-04-02