Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance.
WordlistLoader delivers Amatera via ClearFake ClickFix attacks, while SynkLoader uses Teams phishing to steal Windows login ...
SPECTRE backdoor, deployed by Chinese-speaking hacker group UAT-10147, blinds CrowdStrike Falcon, SentinelOne, and Microsoft ...
A TerminalFix campaign, a ClickFix variant, is using fake Cloudflare CAPTCHA prompts to trick users into executing PowerShell ...
Teams phishing uses fake IT support messages to trick employees into installing SynkLoader through a malicious MSI file.
A previously undocumented malware loader, dubbed SynkLoader, that combines Python, C#, and native C++ components to evade ...