ClickFix Phishing Campaign Masquerading as a Claude Installer
2026-04-16T19:23:48Z•14a9cb751544c1043763b5a055cfc37cdd52e5220f27aec3f7514fa80d929e99
AI-luresCVE-2026-20127ClaudeInsightIDRMDRai-driven-vuln-discoveryanthropicbrowser-vulnerabilitiescisco-sd-wanclickfixdetectionexploitation-in-the-wildmalicious-installermetasploitmicrosoftpatch-tuesdayphishingprioritizationproject-glasswingremediationresponsesocial-engineeringthreat-intelvulnerabilities
What happened
Rapid7 observed a small ClickFix phishing campaign impersonating a Claude installer that used multi-step payload delivery and targeted customers in the EU and US; their MDR/InsightIDR detections stopped further compromise. The feed also highlights Microsoft’s April 2026 Patch Tuesday (167 vulnerabilities, including one known exploited in the wild and one publicly disclosed, with elevated browser vulnerability counts) and Metasploit additions including an exploit module for CVE-2026-20127 (Cisco Catalyst SD‑WAN Controller authentication bypass) recently observed as exploited. Separately, Rapid7
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 14a9cb751544c1043763b5a055cfc37cdd52e5220f27aec3f7514fa80d929e99
- Enrichment time
- 2026-04-16T19:23:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.