FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

ClickFix Malware Campaign: Decentralized Payload Hosting via WordPress Exploitation

A widespread cyberattack campaign has compromised over 5,400 WordPress websites to distribute multi-stage malware using the "ClickFix" social engineering technique. Attackers leverage critical RCE vulnerabilities in plugins—including CVE-2026-14894 (Super Forms) and CVE-2026-32475 (Elementor Pro)—to inject scripts that display deceptive Cloudflare CAPTCHAs or browser error prompts. These lures trick users into manually executing malicious PowerShell or Terminal commands. To ensure resilience, the campaign utilizes "EtherHiding," hosting payloads and C2 resolution on the Polygon and BNB Smart Chain blockchains. Impacted systems are infected with diverse payloads, including DeepLoad, KongTuke (ModeloRAT), and ACR Stealer, targeting both Windows and macOS environments for enterprise credential theft and network intrusion.

AI Brand Impersonation Targeting Anthropic, Claude, and GitHub Developers

Threat actors are leveraging "Brand-as-Bait" infrastructure to target the developer community by impersonating Anthropic’s Claude LLM. By deploying fraudulent GitHub repositories promoting a fictitious "Claude Opus 5" release, attackers distribute RevStealer, a Windows-based information stealer. The attack vector utilizes social engineering via README files and spoofed landing pages to trick users into executing malicious payloads. This results in the exfiltration of browser-stored credentials, cryptocurrency wallets, SSH keys, and sensitive API tokens from developer environments. The campaign has successfully compromised hundreds of organizations, emphasizing the risk of rapid, unvetted AI tool integration and the theft of corporate proprietary secrets.

The Evolution of Polymorphic Phishing-as-a-Service PhaaS and AI-Driven Evasion

Threat actors are pivoting from static phishing to automated, subscription-based Phishing-as-a-Service (PhaaS) frameworks leveraging polymorphism to bypass signature-based and heuristic detection. By utilizing Large Language Models (LLMs) and automated obfuscation engines, these kits dynamically modify code structures, email content, and hosting infrastructure. Advanced threat ecosystems, including Darcula and Lucid, have integrated Adversary-in-the-Middle (AiTM) frameworks for MFA bypass and real-time payment card tokenization scripts. This automation accelerates Account Takeover (ATO) scalability and financial exploitation speed while increasing detection latency due to the non-static nature of the attack signatures.

Iranian APT Screening Serpens Expands Espionage Capabilities with Six New RAT Variants

Iranian-aligned threat actor Screening Serpens has escalated its espionage operations by deploying six distinct Remote Access Trojan (RAT) variants. The campaign utilizes sophisticated social engineering via fraudulent recruitment platforms and fake job sites to target high-value technology professionals in the United States, Israel, and the United Arab Emirates. The malware employs advanced obfuscation, diverse Command and Control (C2) infrastructures, and complex persistence mechanisms to facilitate long-term network presence. This evolution indicates a strategic shift toward highly targeted intelligence gathering, aiming to compromise sensitive intellectual property and national security interests through credential harvesting and lateral movement within critical governmental and corporate infrastructures.


LINK COPIED TO CLIPBOARD