ClickFix Phishing Campaign Masquerading as a Claude Installer

2026-04-16T19:23:48Z14a9cb751544c1043763b5a055cfc37cdd52e5220f27aec3f7514fa80d929e99
AI-luresCVE-2026-20127ClaudeInsightIDRMDRai-driven-vuln-discoveryanthropicbrowser-vulnerabilitiescisco-sd-wanclickfixdetectionexploitation-in-the-wildmalicious-installermetasploitmicrosoftpatch-tuesdayphishingprioritizationproject-glasswingremediationresponsesocial-engineeringthreat-intelvulnerabilities

What happened

Rapid7 observed a small ClickFix phishing campaign impersonating a Claude installer that used multi-step payload delivery and targeted customers in the EU and US; their MDR/InsightIDR detections stopped further compromise. The feed also highlights Microsoft’s April 2026 Patch Tuesday (167 vulnerabilities, including one known exploited in the wild and one publicly disclosed, with elevated browser vulnerability counts) and Metasploit additions including an exploit module for CVE-2026-20127 (Cisco Catalyst SD‑WAN Controller authentication bypass) recently observed as exploited. Separately, Rapid7

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
14a9cb751544c1043763b5a055cfc37cdd52e5220f27aec3f7514fa80d929e99
Enrichment time
2026-04-16T19:23:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.