Skip to content
TrackPodcasts
technologyMar 31, 202618:15

ClickFix Attacks Are Targeting VC and Fintech Talent with New Multi-Stage Loader Techniques

About this episode

This story was originally published on HackerNoon at: https://hackernoon.com/clickfix-attacks-are-targeting-vc-and-fintech-talent-with-new-multi-stage-loader-techniques.
New ClickFix attacks target crypto pros via fake LinkedIn job offers. Learn how multi-stage loaders steal assets and how to protect yourself from these threats.
Check more stories related to cybersecurity at: https://hackernoon.com/c/cybersecurity. You can also check exclusive content about #cybersecurity, #cryptocurrency, #cyber-threats, #clickfix-attacks, #mac-cybersecurity, #macos-malware-threats, #social-engineering-scam, #good-company, and more.

This story was written by: @moonlock. Learn more about this writer by checking @moonlock's about page, and for more stories, please visit hackernoon.com.

ClickFix attacks have become increasingly popular among cybercriminals. They trick users into connecting their Macs to a malicious criminal network. Moonlock Lab uncovers a sophisticated ClickFix scheme that uses fake VC firms and personas to target crypto professionals with fake job opportunities.

Get every episode summarized

Each time The Good Tech Companies publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

222 searchable segments. Every word is indexed and playable.

ClickFix Attacks Are Targeting VC and Fintech Talent with New Multi-Stage Loader Techniques

The Good Tech Companies

0:00
18:15

Full transcript

The Good Tech CompaniesClickFix Attacks Are Targeting VC and Fintech Talent with New Multi-Stage Loader Techniques. Machine-transcribed; use the interactive transcript above to jump the player to any line.

This audio is presented by Hacker Nune, where anyone can learn anything about any technology. Click Fix Attacks are targeting VC and FinTech talent with new multi-stage loader techniques. By Moonlock, by MacPaw. No malware, no vulnerability exploit, no online web downloads. Click Fix Attacks, which have become increasingly popular among cyber criminals, are breaching the computers in big numbers. Their success, and their weakest point, tricking users themselves into connecting their Macs to a malicious criminal network. Once connected to the criminal network, the attackers gain full privilege and access, establish a communication channel, and deploy a series of payloads that steal data and crypto wallet credentials. This multi-stage loader attack uses SmecoS' own language to appear legitimate and raise no flags. It has become a popular and standard technique among criminals who are moving away from standalone malware file downloads. In this report, we look into why new click fix techniques are popular and successful.

We also dive deep into a case example of a recent campaign discovered in the wild by the Moonlock Lab team, which shares notable characteristics with the North Korean State-supported Hacker campaign known as Contagious Interview. Click Fix, who criminals target, and why they are popular in the dark web. In 2024, Microsoft reported that click fix was used as the initial technique in 47% of all attacks they detected. By the first half of 2025, ESET found that click fix attacks had surged by 517% in just six months. The technique, which began as a niche intrusion method in 2023, continued its uptrend use throughout 2025, as both cyber criminals and nation-state threat actors embraced it. But what does a click fix attack look like from the user's point of view? And why are they so popular? The setup is familiar by now. A user lands on a page that looks like a Cloudflare verification, a broken video stream, or a routine browser check. Then the user clicks on the Cloudflare checkbox, and without knowing it, they write a command to

their clipboard that sets up the attack. The fake page then tries to guide users with simple step-by-step instructions on how to open their Mac terminal and paste a script there. All this happens while the click fix window displays a countdown timer to create a false sense of urgency. Who falls for this type of cyber attack? So far, we have seen click fix attack star get high-value Mac users who work in the crypto, blockchain, web3, AI, and software developer industries. However, the technique can be used against any type of user. This is why, tech savvy users, accustomed to using Mac's terminal script, may see no red flag in pasting a script on their terminal because they're used to doing it and work with their terminal every day. On the other hand, the average user may think, well, this is how professionals fix things or download advanced software. This is why click fix works on different types of users. Thread actors love click fix because it requires no zero day, no heavy stand-alone malware file, and can sidestep endpoint detection in response, EDR, antivirus, and Mac's built-in protection

security suite, including gatekeeper and Apple's transparency, consent, and control, TCC. Summarizing, red flags to look out for are, cloud flare, I'm not a robot. Verifications. If you land on a website that asks you to verify that you are not a bot, be cautious. Cyber criminals can hide scripts inside the checkboxes, too. For example, gather information like what OS you are using to later serve you the malware or script that is specific to your OS. Step-by-step instructions that include terminal commands. If a site gives you step-by-step instructions on how to copy and paste a script on your Mac terminal, it is likely a click fix attack. Do not copy terminal commands on your Mac unless you are 100% sure they are safe. Click fix variations. There are several variations of click fix techniques to look out for. Install fix attempts to trick users into copying a script to fix, a browser, driver, webcam, or system issues that do not exist. On the other hand, drag and drop, click fix

asks users to drag a file directly into the Mac terminal. Not all click fix attacks look the same, so look out for variations. Immediate system password. The first thing a multi-stage loader often does is prompt you for your system password. It needs this password to escalate privileges, access, and execute tasks that only the system administrator, you, can execute. Do not type in your password after running a script on your terminal or after installing any software. It starts with a LinkedIn message, fake venture capital and blockchain firms. In their latest investigation, the Moonlock Lab team found a new click fix campaign operating in the wild that was targeting crypto and web three professionals. This click fix attack starts with a message on LinkedIn. Blockchain industry professionals were contacted with a personalized message by Mikhailo Haryev, who is listed on LinkedIn as co-founder and managing partner of Solidbit Capital, a web three and defy focused investment firm. The message and the LinkedIn contact link appear legitimate but are fake and fabricated by the attacker. The personalized message references

projects that those who were contacted actually work on. This gives the message a more human and professional opportunity, establishing trust. The message then opens the door to a fake potential employment or work role opportunity and casually invites users to schedule a call via the legitimate calendar app. As seen in the image below, the calendar link used by the attacker in this case is, which is mentioned above, is leveraging legitimate calendar. Calm infrastructure to send out phishing invites. Besides calendar, calm links, users were offered by the cyber criminals links to fake zoom meetings and fake Google meetings, again abusing known brands to establish fake legitimacy. Another fake persona linked to this campaign, which we found through Hooservice Research when checking registrants of the malicious domain, is Antoly Big Dash. Our online search revealed that Antoly Big Dash is also listed as the founder of Solidbit Capital, the same entity that Mikhailo Haryev claims to represent when engaging victims on LinkedIn. Users who clicked on calendar,

chose a date, time, and filled in their personal data, including name and email, appeared to have later received a fake Google Meet or Zoom Meet link where a click fix technique delivered the malicious multistage loader. As the image above shows, the IOC, still active when this report was being written, prompted users to schedule a date and time, and then asked them to fill in personal data in the form seen above, including name, email, and comments. A broader industrialized campaign AND infrastructure besides the fake personas, the Moonlock Lab team found that attackers, leveraging AI, created a series of fabricated online company identities. This includes the fake Solidbit, Megabit, and Lumac's capital VC firms. As mentioned, Solidbit Capital is the identity tied to the Big Dash registrant and the Mikhailo Haryev linked in persona. Megabit is an additional fake company discovered on the campaign infrastructure. Hosted on the fake Zoom domainet, the site presents itself as an investment firm. The site presents a polished dark-themed frontend, navigation tabs, portfolio,

about us, focus, team, contactus, and login, and an investment team, page featuring four individuals, all displayed with AI-generated headshot photos. The domain variant, O7USWeb, S versus S07Web, S confirms that this is the same operator rotating infrastructure identifiers while reusing the core naming pattern. We also found that attackers had recently created a domain to host the fake Lumac's capital page. The Lumac's capital website, live and fully functional, also looks legitimate and professional, with working navigation, multiple tabs, and a fabricated company history. Note that the headshots in the image above are also AI-generated. What happens when users schedule a meeting with the attackers? Now that we covered the lures and how attackers create rather convincing but fake online companies to establish trust to contact users for fake job offers, let's look at what happens when a user clicks on the calendar links or interacts with specific malicious sites. When a victim clicks the fake Zoom or Google Meet link provided by the LinkedIn

operator, they are directed to a page that appears to be a legitimate event website. In this case, the Digital Acid Conference 3, site reference's Aerocryptocurrency event, while, hedge week, is a well-established hedge fund industry news portal widely read by institutional investors, fund managers, and allocators. MoonLock Lab reached out to hedge week to notify them of the type squad domain abusing their brand, but did not receive a response at the time of publication. The attackers overlay the fake pages with a fake cloud flare branded verification modal. When a user clicks on the, I'm not a robot, checkbox, the attackers page silently runs a JavaScript that writes a malicious command on the user clipboard The command is oxygen mono-sulfide specific. This means the script detects the operating system of the user via the user agent string, and then loads a click-fix attack that includes a script that matches the user's operating system. Basically, if you are running Windows, you get a Windows OS script, while if you are running AMAC, you get a Mac OS script.

The attack is therefore cross-platform. The image below shows a click-fix technique targeting Windows users, but as mentioned, attackers gain knowledge of what OS the user is using when they click on the, I'm not a robot, checkbox. Users who copy and paste the script on their terminal will, without knowing it, trigger the cyber attack, which executes stealthily in the background. Users are even redirected to a legitimate site to hide the attack. While in the past, we have observed click-fix campaigns that infected users with Mac OS Steelers like Maxink. This campaign is different. On Mac OS, the bash one-liner checks for Python 3, installs homebrew from if needed, weaponizing a trusted developer tool is cover. It then pulls a Python script from the same C2 via curl-h user agent. Macintosh saves it to, and runs it under, no hubbash and, so it persists after the terminal closes. A technical deep dive into the Mac OS payload the fake zoom app, first flagged by at Mal WR Hunter team and analyzed by at L0SEC, is a swift application that uses SwiftUI to render a

credential harvesting dialogue mimicking a native Mac OS password prompt. The prompt is coded to Windows shake if the user types in the incorrect password entry. Once those impacted type in their credentials, these are captured and exfiltrated to a telegram bot. The payload server at served Mac OS, Windows, and Linux payloads from the same endpoint via a numeric parameter. Moonlock Lab continued analysis on two additional Mac OS binaries linked to this exact campaign, after they had been shared by at Mal WR Hunter team as related to fake zoom domains. Property obfuscated version non-obfuscated VRSIO and SHA2569A778D2B799197717E95072E4deco1c815A5FD81F574B53810176552D73D8DC874B62FB3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3D3

4E9DBF5744CF1,540,941FB43A793B27E13E937,299,167B2B67CB84D6B file size 93MB376KB both samples perform the same core functions, retrieving a temporary directory path, downloading files from a remote server, resigning them with ad hoc code signatures, and executing them. The critical difference is in their construction, the obfuscated version, 9. Three megabytes is inflated with garbage instructions distributed across two binary segments. This junk code is designed to bypass static analysis tools. Disassemblers like Geedra struggle to process the binary efficiently, making quick triage and practical. A scan on virus total revealed that the sample itself was undetected by all major security

engines at the time of discovery. The non-obfuscated version, 37. Six kilobytes, contains the same functional logic without the padding. It appears to be either a development build or an earlier iteration of the payload. Again, this sample was also undetected by most major security engines on virus total at the time of discovery. Why both versions were uploaded to virus total remains unclear. Both achieved zero detections across all vendors for an extended period after submission, demonstrating that the threat actors have invested in evasion techniques that effectively bypass current static analysis heuristics. Attribution. A signature that's been seen BEFORUN February 9, 2026. Mandy and published findings on AffinTech Intrusion attributed to UNC 1069. A DPRK linked actor tracked since 2018. Below, we note how both campaigns share notable similarities in techniques and malware and signal to attribution likelihood. Element this campaign mandient, UNC 1069 fake zoom domain zoom.

SO7 web, US zoom, USWEO5, US domain pattern zoom. Us, XX, web, US zoom, USWEO, XX. A social engineering linked in right-pointing arrow, calendar-right-pointing arrow, fake zoom telegram, right-pointing arrow, calendar-right-pointing arrow, fake zoom delivery click-fix, fake cloud flare capture, click-fix, fake audio troubleshooting, OS targeting Mac OS plus Windows Mac OS plus Windows target sector crypto, web 3 crypto startups, developers the domain naming pattern, zoom. Us, XX, web, US versus zoom, USWEO, XX. Us, is not coincidental. Definitive attribution remains open, but the tradecraft overlap is documented. This is what a DPRK adjacent playbook looks like when it runs through a polished social engineering layer. Recommendations and mitigation actions for users. Click fix campaigns reach the terminal stage because everything before it, including

the LinkedIn message, the calendar link, and the polished company website, has already cleared the target's informal trust threshold. By the time the capture appears, skepticism is spent. Despite its sophistication and the weaponization of Mac OS's own processes and language, there are still several things any user can do to stay safe from this cyber attack. Know the risks of running scripts on your MACC terminal whether you are a technically well-versed user or not, by understanding the risks of running scripts on your MAC terminal. You can strengthen your cyber security. Apple itself appears to be trying to raise awareness on the risks of terminal commands with a new feature that warns users about the risks of pasting scripts in their terminal. The feature is reported to be working only on Mac OS Tahoe 26. 4. And Apple has released no official press release on how it works, or if they have plans to make this feature standard across all MAC OS versions, which would be a much welcomed and useful addition if released across the board. IF a script looks like gibberish, it's probably malicious legitimate terminal macOS scripts

are transparent and readable. If you come across a terminal script that looks like random letters, numbers, and symbols, this means it has been scrambled to hide something and is probably malicious. A Val and Base 64 decode Red flag command SIF you see a script that contains commands of Val, Bash, or Base 64 decode, do not run it on your terminal. The command of Val gives a script permission to, run whatever follows as a program. This is not normal or used in safe scripts. The command base 64 decode, found at the end of the scripts, is the scrambler, and why you see the script as a random string of letters instead of what it actually says. Verify J-O-B offers unfortunately, in this day and age, if you get a job offer, you have to double check and verify everything, and once you are done with that, do it again. Cyber criminals, from nation-state supported actors to common scammers, are constantly praying on the job market and are well resourced and skilled at what they do. criminals have also embraced AI, which allows them to create fake pages and fake personas

in just minutes. Applying zero trust and checking everything not twice but three times is highly recommended. Here are the steps you can take to stay safe. Verify the company. Check when the domain was registered, review the company's digital footprint, and look closely at team photos or biographies that maybe AI generated or recently fabricated. Be cautious if a conversation quickly moves off LinkedIn. If the sender insists on using their Zoom, calendar, or Google Meet, run those external links through a URL checking tool. Treat urgency as a red flag. Pressure to schedule quickly, move to private channels, or follow specific technical instructions to change settings on your device is often a key part of the manipulation. Never paste commands into your terminal. No legitimate service will require you to open your terminal and run a command as part of a verification process. The rule of thumb is to pause before doing anything you don't fully understand. If a step feels unusual for a job interview, a partnership call, or an investment discussion,

it probably is. Conclusion. Click fix attacks and multi-stage loaders, combined with sophisticated eye-driven social engineering, have become a golden standard in the dark web. Cyber criminals tend to stick with what works, so know that these techniques are likely to evolve and not disappear. What exactly the next click fix technique will look like is still unknown, but by understanding how the cyberattack works, you can build up your security posture. Thank you for listening to this Hackernoun story, read by Artificial Intelligence. Visit Hackernoun.com to read, write, learn, and publish.

More episodes

More from The Good Tech Companies

View all episodes →