ClickFix campaign abuses Deno runtime for infostealer delivery
2026-08-13T08:51:36Z•b6fc30d50ca2bd0cb5b7e46ca894b3bacaf49344dbb3db85d18cebb7270d28cb
CVE-2026-18577AI securityClickFixDenoGOLD EMBRACEInterlock ransomwareLOLBinsN-able N-centralPythonRMMSophoscompromised WordPressdouble extortionfileless executioninfostealernetwork tunnelingremote access
What happened
Sophos reports multiple active threat developments, including a ClickFix campaign using compromised WordPress sites to install the Deno runtime and deliver a Python-based infostealer, abuse of alternative runtimes and LOLBins for fileless execution, Interlock ransomware activity involving legitimate DFIR tools, and exploitation of N-able N-central via CVE-2026-18577 to deploy RMM tools and network tunnels for persistent remote access. The feed also includes defensive and AI security announcements.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sophos_news
- Record identifier
- b6fc30d50ca2bd0cb5b7e46ca894b3bacaf49344dbb3db85d18cebb7270d28cb
- Enrichment time
- 2026-08-13T08:51:36Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.