Hackers use "ClickFix" technology to impersonate VC and hijack QuickLens extensions, stealing cryptocurrencies.

TechubNews

Techub News reports that hackers are stealing cryptocurrencies through the “ClickFix” attack method. Recent cases include impersonating venture capital firms and hijacking browser extensions. Moonlock Lab revealed that scammers are pretending to be fake VCs like SolidBit, MegaBit, Lumax Capital, etc., contacting users via LinkedIn to offer collaboration opportunities, then guiding them to click on fake Zoom or Google Meet links. After users enter the page, they encounter a fake Cloudflare “I’m not a robot” verification box; clicking it maliciously copies commands to the clipboard and tricks users into opening a terminal to paste and execute, completing the attack. This method bypasses traditional security defenses, prompting victims to actively execute malicious payloads. Additionally, hackers hijacked the Chrome extension QuickLens (about 7,000 users), embedding malicious scripts in the new version to search for cryptocurrency wallets, seed phrases, Gmail inboxes, YouTube data, and login credentials/payment information from forms. The extension has been removed from the Chrome Web Store. ClickFix has been popular since last year, affecting thousands of businesses worldwide across multiple industries.

View Original
Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)