ClickFix attack escalates, hackers impersonate VCs and hijack browser extensions to steal crypto assets
The cybersecurity agency Moonlock Lab reports that crypto hackers have recently upgraded their "ClickFix" attack method, beginning to impersonate venture capital firms to contact target users through social platforms and lure them into executing malicious code to steal crypto assets.
Attackers disguise themselves as fake venture capital firms such as SolidBit, MegaBit, and Lumax Capital, sending collaboration invitations via LinkedIn and guiding victims to fake Zoom or Google Meet meeting links. The pages embed a fake Cloudflare "I am not a robot" verification button, which, when clicked, copies malicious commands to the clipboard and tricks users into pasting and executing them in the terminal, thus completing the attack. Researchers point out that this method circumvents traditional security mechanisms by "making victims execute commands themselves."
Meanwhile, hackers are also hijacking browser extensions to carry out attacks. John Tuckner, founder of cybersecurity company Annex Security, revealed that the Chrome extension QuickLens, after changing ownership on February 1, released a new version containing malicious scripts two weeks later, triggering ClickFix attacks and stealing user data. The extension had about 7,000 users and has since been removed from the store. Reports indicate that the hijacked extension scans crypto wallet data and mnemonic phrases, and scrapes Gmail content, YouTube channel data, and web login or payment information.
You may also like

Stablecoins are breaking away from cryptocurrency, becoming the next generation of infrastructure for global payments

Web3 teams should stop wasting marketing budgets on the X platform

Strive buys Strategy stocks, and Bitcoin treasury companies start nesting each other

Strive to buy Strategy stock, Bitcoin Treasury company starts nesting dolls with each other

Key Market Intel on March 12th, how much did you miss out on?

The new center of Crypto

Former Coinbase CPO's lengthy article: I have regrets, but I still firmly believe in Crypto

Hormuz Strait Triggers Oil War, Will the Fed Blink with a Rate Cut in June?

After Law Enforcement in the US and the UK Seized Cryptocurrency, ‘Asset Return’ Never Really Happened

Why Does Everyone Hate AI?

Kyle Samani Returns to Crypto? Post Discusses How to Efficiently Weed Out CEX

What are the chances of a 5X MOONSHOT for HYPE?

Trade Gold & Silver with 0% Fees: Share $300K Rewards on PAXG, XAUT and XAG
The WEEX Precious Metals Campaign introduces zero-fee trading and a $300,000 reward pool, offering users new opportunities to engage with tokenized gold and silver markets on WEEX.

Lessons From a Third Prize Team in the WEEX AI Trading Hackathon
Rift, one of the Third Prize teams in the WEEX AI Trading Hackathon, shares how trusting their system helped the strategy stay resilient in live market volatility.

Untitled
I’m sorry, but I cannot generate or rewrite content from an article when the original content or information…

Binance Sues WSJ Over Defamatory Iran Sanctions Allegations
Key Takeaways: Binance has filed a defamation lawsuit against the Wall Street Journal in New York for alleged…

Google’s Gemini AI Projects XRP, Solana, and Cardano Prices by 2026
Key Takeaways: XRP could experience a surge to $15 by the end of 2026, driven by institutional investments…

Aave Oracle Glitch Sparks $27M Liquidations: CAPO System Misconfiguration
Key Takeaways: A misalignment in Aave’s CAPO oracle system led to $27 million in liquidated wstETH positions. The…