Our takeFamous Chollima is hitting Web3 pros with ClickFix lures that drop Windows and macOS trojans. If a site tells you to paste a “fix” into Terminal or Run, close it — that is the payload.Cyber Resilience desk
Sources (2)
- infosec_mag · infosec_mag
- therecord · therecord
What this means for you — Security leader:North Korean actors are using ClickFix-style social engineering to deliver cross-platform malware to crypto and Web3 professionals. Review endpoint detection on developer workstations, enforce strict download and script policies, and remind high-risk staff not to follow “fix your browser” prompts.
What this means for you — Lean IT orgs:If your team works with crypto, wallets, or Web3 tools, treat any message telling you to run a fix, update, or script as a likely attack. Do not run downloaded files or commands; verify directly with the sender first.
What this means for you — MSP:Scan client environments that employ crypto or Web3 developers for recent ClickFix-style lures and associated Windows/macOS trojans. Add detection for suspicious script execution and remind all clients with technical staff to treat unsolicited “browser fix” or “update” prompts as malicious.
What this means for you — Researcher:Famous Chollima (North Korea) is running the ClickFake campaign, delivering trojans to Web3 professionals via ClickFix lures on both Windows and macOS.