Current ClickFix Threat Landscape Developments

Executive Summary In the last two years, ClickFix tactics have moved from a one-off social engineering trick into an industrialized attack ecosystem that is outpacing conventional antivirus and endpoint defenses. The technique first appeared in late 2023 and early 2024, and it skips exploits and vulnerabilities entirely as a fake webpage impersonating a CAPTCHA check, browser update…

Read More

New ClickLock Stealer macOS Malware Spread via ClickFix Campaign

Executive Summary On 9 June 2026, Group-IB Threat Intelligence reported a malicious shell script uploaded to VirusTotal assessed as a new modular macOS stealer likely distributed via ClickFix phishing pages, relying on compromised WordPress domains and Telegram infrastructure, with a strong European victim focus. According to Group-IB, a ClickLock Stealer operation has already targeted at least 100…

Read More

ShinyHunters Abusing OAuth to Compromise SaaS Apps

Executive Summary On 13 July 2026, Microsoft researchers published details of a ShinyHunters campaign active between mid-2025 and mid-2026 targeting customer SaaS-based applications, especially Salesforce instances, through voice phishing (vishing), supply chain compromise, and misconfigured guest access. The threat actors abused trusted OAuth relationships for unauthorized access, data exfiltration, and persistence.  ShinyHunters has demonstrated a consistent pattern…

Read More

Residential Proxy Networks Are Enabling Account Takeover That Perimeter Controls Cannot See

Accertify, a fraud decisioning platform provider, has identified a sustained shift in account takeover (ATO) infrastructure: attackers are moving away from datacenter/hosting IPs and toward commodified residential proxy networks, allowing credential-stuffing and login-based attacks to pass through perimeter security without triggering velocity or reputation-based controls. Analysis of internal Accertify client data from 2024–2025 shows this…

Read More

Protecting Retail and Hospitality Front Lines From Conversational AI Threats

Executive Summary The retail and hospitality sectors operate on high-velocity human interaction, making their front lines a major target for sophisticated social engineering attacks. Historically, organizations have relied on annual compliance videos and predictable phishing simulations to train frontline workers. While they were initially valuable, this type of traditional training no longer matches how attacks…

Read More