Social Engineering Examples

ClickFix & SEO Poisoning: Real Attack Examples

ClickFix and SEO poisoning attacks get a victim to infect their own machine: a fake CAPTCHA or error message that walks them through pasting a malicious command into Windows Run, or a poisoned search result that ranks a booby-trapped download above the real one. This family includes the long-running Gootloader campaigns against law firms and several 2024-2026 fake-software and fake-job-interview schemes.


8 Cases
CA
Confirmed

UAC-0050 ClickFix Fake-reCAPTCHA Campaign Deploys 'Lucky Volunteer' Infostealer Against Ukrainian Organizations

A Ukrainian-language "shared document" phishing wave used a fake reCAPTCHA "verify you are human" ClickFix page to trick victims into pasting and running.

Incident 2024Read →
CA
Confirmed

Lampion Banking Trojan ClickFix Campaign vs Portuguese Government, Finance and Transport Sectors

A revived Lampion banking-trojan campaign spoofed Portugal's tax authority site to trick victims into pasting a PowerShell command into the Windows Run.

Incident 2025Read →
CA
Confirmed

GootLoader SEO Poisoning of Legal Services Firms

GootLoader operators hijacked Google search rankings for legal-agreement phrases.

Incident 2021Read →
CA
Confirmed

GootLoader and SocGholish Dual Campaign Against Six Law Firms (2023)

eSentire's Threat Response Unit blocked 10 separate attacks across six unnamed law firms in Jan-Feb 2023, foiling two parallel campaigns.

Incident 2023Read →
CA
Confirmed

Fake AnyDesk Installer to MetaStealer: FileFix/search-ms Variant of ClickFix

A victim searching for the AnyDesk remote-access tool hit a typosquatted site with a fake Cloudflare Turnstile.

Incident 2025Read →
CA
Confirmed

Fake ChatGPT Download Site (openew[.]app): SEO Poisoning, Malvertising, and an AI-Generated chatgpt.com Redirect Deliver Cross-Platform Infostealers with Wallet-Swap Payload

A convincing fake ChatGPT download site, openew[.]app -- reached in part via an AI-generated fake outage page rendered on a real chatgpt.com/s/ URL --.

Incident 2026Read →
CA
Confirmed

North Korea's 'Contagious Interview' ClickFix Fake Job-Assessment Campaign Targets Crypto Industry (2025)

Lazarus-linked operators built polished fake job-interview sites impersonating Coinbase, Kraken, Circle and other crypto firms.

Incident 2025Read →
CA
Confirmed

Gootloader Returns After 7-Month Hiatus: SEO Poisoning, Glyph-Swapped Fonts, and a Dual-Personality Malformed ZIP (2025)

After going quiet in March 2025, Gootloader returned in November 2025 with a glyph-swapping web font and a malformed ZIP to hide malware.

Incident 2025Read →

ClickFix Fake-Verification and Installer Lures

The UAC-0050 ClickFix campaign used a fake reCAPTCHA to deploy the Lucky Volunteer infostealer against Ukrainian organizations, the Lampion banking trojan used the same ClickFix technique against Portuguese government and finance targets, a FileFix/search-ms variant delivered MetaStealer through a fake AnyDesk installer, and a fake ChatGPT download site combined SEO poisoning and malvertising to deliver cross-platform infostealers.

SEO Poisoning of Legal and Professional Services

GootLoader has run a long campaign of SEO poisoning against legal services firms, a dual GootLoader and SocGholish campaign hit six law firms in 2023, and GootLoader returned after a seven-month hiatus in 2025 with glyph-swapped fonts and a malformed ZIP file.

Nation-State Fake Job-Interview Lures

North Korea ran the Contagious Interview campaign, using a fake job-assessment ClickFix lure to target the crypto industry with the same self-infection technique used against law firms and Ukrainian organizations.

Explore more

Browse the rest of the library