FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

ClickFix Malware Campaign: Decentralized Payload Hosting via WordPress Exploitation

A widespread cyberattack campaign has compromised over 5,400 WordPress websites to distribute multi-stage malware using the "ClickFix" social engineering technique. Attackers leverage critical RCE vulnerabilities in plugins—including CVE-2026-14894 (Super Forms) and CVE-2026-32475 (Elementor Pro)—to inject scripts that display deceptive Cloudflare CAPTCHAs or browser error prompts. These lures trick users into manually executing malicious PowerShell or Terminal commands. To ensure resilience, the campaign utilizes "EtherHiding," hosting payloads and C2 resolution on the Polygon and BNB Smart Chain blockchains. Impacted systems are infected with diverse payloads, including DeepLoad, KongTuke (ModeloRAT), and ACR Stealer, targeting both Windows and macOS environments for enterprise credential theft and network intrusion.

The Infostealer Malware Pipeline: From Endpoint Infection to Value-Added Marketplace Intelligence

Infostealer malware pipelines industrialize the theft of endpoint data to create high-fidelity intelligence for initial access brokers (IABs). Using vectors such as cracked software and malicious browser extensions, these payloads harvest browser credential stores, session cookies for MFA bypass, and system fingerprints. Raw logs are processed through C2 dashboards for automated parsing and enrichment, cross-referencing stolen data with professional identities to escalate market value. This process facilitates a rapid 48-hour monetization window, fueling credential stuffing and providing the primary entry vector for ransomware-as-a-service (RaaS) operations, with an estimated 2.86 billion credentials circulating in criminal markets.

Infostealer Compromise of Blind Eagle Malware Production Pipeline

A critical intelligence reversal has occurred where commodity infostealer campaigns—utilizing variants such as RedLine, Lumma, and Stealc—successfully compromised the development environment of the Blind Eagle APT. Utilizing delivery vectors including malicious GitHub repositories and impersonated brand lures, attackers exfiltrated high-value session cookies, SSH keys, and API tokens from Blind Eagle operators. This breach directly exposed the group's backend malware production pipeline, revealing build scripts, C2 management panels, and code signing certificates. This event demonstrates a potent "infostealer-to-APT" pipeline, where low-level commodity malware facilitates the breach of high-level state-sponsored infrastructure, allowing defenders to proactively generate signatures for future malware generated by this specific build system.

AI Brand Impersonation Targeting Anthropic, Claude, and GitHub Developers

Threat actors are leveraging "Brand-as-Bait" infrastructure to target the developer community by impersonating Anthropic’s Claude LLM. By deploying fraudulent GitHub repositories promoting a fictitious "Claude Opus 5" release, attackers distribute RevStealer, a Windows-based information stealer. The attack vector utilizes social engineering via README files and spoofed landing pages to trick users into executing malicious payloads. This results in the exfiltration of browser-stored credentials, cryptocurrency wallets, SSH keys, and sensitive API tokens from developer environments. The campaign has successfully compromised hundreds of organizations, emphasizing the risk of rapid, unvetted AI tool integration and the theft of corporate proprietary secrets.


LINK COPIED TO CLIPBOARD