Hackers impersonate VC and hijack the QuickLens plugin, using ClickFix technology to steal cryptocurrency assets
According to Cointelegraph, hackers are using the "ClickFix" attack method to steal cryptocurrencies, with the latest two attacks involving impersonating venture capital firms and hijacking browser extensions.
Cybersecurity company Moonlock Lab reports that scammers impersonate fake VCs such as SolidBit, MegaBit, and Lumax Capital, contacting users via LinkedIn to offer collaboration opportunities, then directing them to click on fake Zoom and Google Meet links. After clicking the link, users are led to a page with a forged Cloudflare "I'm not a robot" verification box; clicking this box copies malicious commands to the clipboard and prompts users to open a terminal to paste the so-called verification code, thus executing the attack.
Moonlock Lab points out that this method turns victims into execution mechanisms, bypassing defenses in the security industry. Meanwhile, hackers are also spreading malware by hijacking the Chrome extension QuickLens. This extension allows users to run Google Lens searches directly in the browser, and after ownership was transferred, the new version contains malicious scripts that can initiate ClickFix attacks and steal information.
The extension has about 7,000 users, and once hijacked, it searches for cryptocurrency wallet data and recovery phrases to steal funds, as well as scraping Gmail inbox content, YouTube channel data, and login credentials or payment information entered in web forms. The extension has been removed from the Chrome Web Store. The ClickFix technique has been popular among hackers since last year, forcing victims to manually execute malicious payloads, affecting thousands of businesses and multiple industries worldwide.
You may also like

Stablecoins are breaking away from cryptocurrency, becoming the next generation of infrastructure for global payments

Web3 teams should stop wasting marketing budgets on the X platform

Strive buys Strategy stocks, and Bitcoin treasury companies start nesting each other

Strive to buy Strategy stock, Bitcoin Treasury company starts nesting dolls with each other

Key Market Intel on March 12th, how much did you miss out on?

The new center of Crypto

Former Coinbase CPO's lengthy article: I have regrets, but I still firmly believe in Crypto

Hormuz Strait Triggers Oil War, Will the Fed Blink with a Rate Cut in June?

After Law Enforcement in the US and the UK Seized Cryptocurrency, ‘Asset Return’ Never Really Happened

Why Does Everyone Hate AI?

Kyle Samani Returns to Crypto? Post Discusses How to Efficiently Weed Out CEX

What are the chances of a 5X MOONSHOT for HYPE?

Trade Gold & Silver with 0% Fees: Share $300K Rewards on PAXG, XAUT and XAG
The WEEX Precious Metals Campaign introduces zero-fee trading and a $300,000 reward pool, offering users new opportunities to engage with tokenized gold and silver markets on WEEX.

Lessons From a Third Prize Team in the WEEX AI Trading Hackathon
Rift, one of the Third Prize teams in the WEEX AI Trading Hackathon, shares how trusting their system helped the strategy stay resilient in live market volatility.

Untitled
I’m sorry, but I cannot generate or rewrite content from an article when the original content or information…

Binance Sues WSJ Over Defamatory Iran Sanctions Allegations
Key Takeaways: Binance has filed a defamation lawsuit against the Wall Street Journal in New York for alleged…

Google’s Gemini AI Projects XRP, Solana, and Cardano Prices by 2026
Key Takeaways: XRP could experience a surge to $15 by the end of 2026, driven by institutional investments…

Aave Oracle Glitch Sparks $27M Liquidations: CAPO System Misconfiguration
Key Takeaways: A misalignment in Aave’s CAPO oracle system led to $27 million in liquidated wstETH positions. The…