--[ Anomaly #13 - ClickFix between campaigns ]--

July 27, 2026

By: ZoqueLabs

This writing is distributed under a Creative Commons CC BY-SA (Acknowledgment - Share Alike) license.

Spanish version

 

There are techniques that appear once and disappear. Others begin to repeat themselves until it is no longer possible to ignore them. That happened to us this week with ClickFix.

We don’t remember exactly when we first started seeing it. It probably appeared as another detail within some malware campaign. Then he appeared again in another. Then in a different one. The groups changed, the victims and the type of malware used changed, but there was something constant: Clickfix.

The infection no longer started with a sophisticated exploit or an Office document full of macros. It started with something that seemed like a “solution”.

A page that says the browser needs an update. A video call that requires installing an additional component. A message that asks to copy a command into PowerShell to resolve an error. A repository that looks legitimate. An installer of a tool that thousands of people use every day.

And that’s where the interesting thing happens. For a long time, social engineering was about convincing someone to open a file or click a link. ClickFix seems to move that border a bit. The victim no longer just downloads something: he follows a series of instructions that, apparently, form part of a completely normal technical procedure. The attacker stops looking like an attacker and starts looking like technical support.

In recent months we have found this pattern in campaigns that we have followed since Anomaly. Some use fake pages, others repositories that imitate real projects, and others distribute modified installers of widely used software. In this issue, for example, Cisco Talos documented a campaign that uses trojanized versions of Zoom, WebEx, MobaXterm, and DBeaver to deploy Starland RAT and other implants using a ClickFix-based chain.

We don’t think the name of the malware is the most important thing in that story. In a few months we will probably be talking about another RAT, another stealer or another different family. What seems to remain is the idea of constructing a credible problem for the victim themselves to complete the first step of the infection.

That also explains why we find ClickFix interesting. It does not depend on a specific vulnerability or a specific application. It can appear around GitHub, a remote administration tool, a video conferencing client, or any software that is part of the daily work of those who develop, manage systems, or simply use a computer. The story changes; the mechanism remains.

We don’t have enough material to say that ClickFix is going to become the new initial access standard. We also don’t know how long this trend will last. But we do find it striking that different campaigns, developed by different actors, are reaching a similar conclusion: sometimes it is easier to convince someone to execute a command than to find a vulnerability that allows it to do so automatically.

We will continue to observe it. Because when the same idea starts to be repeated in different places, it is usually worth reviewing it. Various anomalies usually appear there.

--[State, surveillance and spyware ]–

New documents reconstruct Pegasus’ arrival in Panama

An international investigation published new documents about one of Pegasus’ first sales in Latin America. These include the contract signed by the Security Council of Panama in 2012, a license to compromise up to 300 devices and screenshots of the interface used by the operators. According to the report, this material documents operations directed against presidential campaigns, electoral officials and political figures in the country, and provides new context about the early expansion of commercial spyware in the region.

--[Malware ]–

An infostealer for macOS reuses Telegram sessions

SlowMist researchers analyzed an infostealer for macOS that, in addition to extracting credentials and data from cryptocurrency wallets, reuses local Telegram Desktop sessions. Instead of breaking 2FA or stealing the password, the malware copies session files (tdata) and restores them to another computer, allowing access to the account without going through the authentication process again. The same campaign also replaces legitimate Ledger and Trezor apps with fake versions to capture recovery phrases (seed phrases) from wallets.

GitHub, ClickFix and seed phrases: the combination of OkoBot

Kaspersky documented OkoBot, a modular framework made up of about 20 modules aimed at stealing cryptocurrency wallets. The campaign distributes the malware from fake repositories on GitHub and uses the ClickFix technique to convince victims to execute malicious commands on their own computers. Among the modules, SeedHunter stands out, designed to capture wallet recovery phrases such as Ledger and Trezor using fake interfaces, as well as components for keylogging, monitoring the clipboard and extracting credentials. Investigators identified victims in Brazil and Mexico, among other countries, and link this operation to the TookPS campaign observed since 2025.

ClickFix continues to expand as a malware distribution vector

Cisco Talos documented a campaign attributed to actor UAT-11795 that distributes Trojanized installers of applications such as Zoom, WebEx, MobaXterm and DBeaver using ClickFix techniques. The infection chain deploys new implants such as Starland RAT and WLDR, aimed at stealing credentials, cryptocurrency wallets and authenticated sessions. The research also highlights the use of a smart contract in Polygon to obtain backup domains from the C2 and Telegram bots to receive information from victims, a combination that shows how operators continue to diversify their infrastructure to make it difficult to disrupt. Among the affected countries is Venezuela.

--[Leaks ]–

Argentina, Uruguay, Peru, Chile - Leaked Latin American data, now available via API

PampaLeaks, an actor we’ve previously registered with Exfiltradaz, began offering in Spear[.]cx an API access service to a database that it claims brings together more than 230 million records from Argentina, Uruguay, Peru and Chile](https://www.brinztech.com/breach-alerts/brinztech-alert-launch-of-samaritan-api-offering-unauthorized-access-to-latam-citizen-data/). Access is sold by subscription and allows you to consult personal information through dozens of endpoints. The actor says that the data comes from government sources and telecommunications companies such as Claro and Movistar, and has already announced that he plans to expand coverage to more Latin American countries. Although the content has not been independently verified,the move from selling entire databases to offering them as a query service marks another way to market stolen data.

--[Threats ]–

Brazil — PhantomEnigma evolves by abusing government infrastructure

ANY.RUN published research on PhantomEnigma, an active campaign in Brazil that switched from distributing a banker using browser extensions to using compromised websites and email accounts .gov.br to deliver a modular backdoor based on Node.js. The report documents more than 20 government portals used as distribution infrastructure, frequent rotation of C2 servers and payloads capable of downloading additional components and running JavaScript. The study shows an evolution in delivery techniques: leveraging compromised legitimate infrastructure increases credibility of the campaigns and makes their detection considerably more difficult.

--[Ransomware ]–

Colombia and Mexico - Extortion with legitimate tools

Kaspersky documented two extortion incidents that occurred in Colombia and Mexico where attackers took advantage of insecure settings —an exposed RDP service and a misconfigured MSSQL server— to access infrastructure and encrypt systems using BitLocker, the encryption tool built into Windows, instead of deploying its own ransomware. In both cases, ransom notes were sent to the printers of the affected organizations.

--[ ZOLIM - This week’s snapshot (07/264/2026) ]–

ZOLIM reports 10 new IPs. Interesting things in this snapshot:

There is much more to explore! You can consult all the information and explore by country, IP, city, threat and other filters in the ZOLIM. dashboard