Two separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic.

September 8, 2026

Two recently uncovered campaigns use ClickFix-style attacks to steal credentials and cryptocurrency as well as to go deeper into the enterprise network to maintain long-term persistence in compromised systems. The attacks, while separate, demonstrate how threat actors continue to evolve the social engineering tactic to exploit commonly used services and engage in more complex malicious activities.

Researchers from Cisco Talos discovered both campaigns, which use different delivery methods, but both rely on the victim to take a seemingly routine action to compromise themselves, according to two separate reports by the networking firm's threat research lab published today. The link between the two was not only in their use of social engineering attacks, commonly known as ClickFix and ClearFake, but also in how they abused legitimate services and assets to make the malicious activity resemble typical user or application behavior, according to the researchers.

Related:ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain