Tag: ClickFix Campaign

Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign
News

Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign

A widespread campaign is using Ghost CMS's serious SQL injection vulnerability (CVE-2026-26980) to insert malicious JavaScript code that initiates ClickFix attack flows. XLab threat intelligence analysts at the Chinese cybersecurity firm Qianxin found the campaign and verified its impact on over 700 domains, including media sources, fintech companies, university portals, AI/SaaS enterprises, security sites, and individual blogs. The researchers claim that malicious code was inserted by threat actors on the websites of DuckDuckGo, Harvard University, Oxford University, and Auburn University. Ghost 3.24.0 through 6.19.0 are affected by CVE-2026-26980, which let unauthenticated attackers to read any data from the website database, including the admin API keys. This key can be use...
New EVALUSION ClickFix Campaign Delivers Amatera Stealer and NetSupport RAT
News

New EVALUSION ClickFix Campaign Delivers Amatera Stealer and NetSupport RAT

Cybersecurity experts have found malware campaigns that use Amatera Stealer and NetSupport RAT through the now-common ClickFix social engineering technique. This month, eSentire is monitoring the activity under the name EVALUSION. Amatera, which was first discovered in June 2025, is thought to be a development of ACR (short for "AcridRain") Stealer, which was offered under the malware-as-a-service (MaaS) model until its sales were halted in mid-July 2024. Subscription prices for Amatera range from $199 per month to $1,499 for a year. According to the Canadian cybersecurity provider Amatera, threat actors can target crypto-wallets, browsers, messaging apps, FTP clients, and email services with its comprehensive data exfiltration capabilities. Notably, Amatera uses sophisticated...