New ClickFix attack Hides in Native Windows Tools to Reduce Detection Risk
2026-04-24T20:51:45Z•a0ad82e5e25c28483f7876c71efa40fac1ed4b64aeb9e2cfa49befc15ff0bc9e
ai-securityanthropicbitwardencmdkeycredential-theftddosdependabotdependency-poisoningdll-sideloadinggograharvester-aptlinux-malwareliving-off-the-landlotuslitemalwaremustang-pandapersistencephishingprompt-injectionregsvr32shai-huludsupply-chainvendor-breach
What happened
Multiple security incidents reported by HackRead: a ClickFix phishing/CAPTCHA scam uses native Windows tools (cmdkey, regsvr32) for persistence to evade detection; TeamPCP compromised the Bitwarden CLI and abused GitHub Dependabot to deploy Shai‑Hulud and poison AI coding tooling; Harvester APT deployed new GoGra Linux malware targeting South Asia via fake PDFs/Microsoft APIs; Mustang Panda updated LOTUSLITE DLL‑sideloading backdoor targets Indian banks and Korean diplomats; Forcepoint disclosed hidden‑website prompt‑injection attacks against AI assistants; Anthropic is investigating a vendor/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- a0ad82e5e25c28483f7876c71efa40fac1ed4b64aeb9e2cfa49befc15ff0bc9e
- Enrichment time
- 2026-04-24T20:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.