ClickFix and SEO poisoning attacks get a victim to infect their own machine: a fake CAPTCHA or error message that walks them through pasting a malicious command into Windows Run, or a poisoned search result that ranks a booby-trapped download above the real one. This family includes the long-running Gootloader campaigns against law firms and several 2024-2026 fake-software and fake-job-interview schemes.
A Ukrainian-language "shared document" phishing wave used a fake reCAPTCHA "verify you are human" ClickFix page to trick victims into pasting and running.
CAA revived Lampion banking-trojan campaign spoofed Portugal's tax authority site to trick victims into pasting a PowerShell command into the Windows Run.
CAGootLoader operators hijacked Google search rankings for legal-agreement phrases.
CAeSentire's Threat Response Unit blocked 10 separate attacks across six unnamed law firms in Jan-Feb 2023, foiling two parallel campaigns.
CAA victim searching for the AnyDesk remote-access tool hit a typosquatted site with a fake Cloudflare Turnstile.
CAA convincing fake ChatGPT download site, openew[.]app -- reached in part via an AI-generated fake outage page rendered on a real chatgpt.com/s/ URL --.
CALazarus-linked operators built polished fake job-interview sites impersonating Coinbase, Kraken, Circle and other crypto firms.
CAAfter going quiet in March 2025, Gootloader returned in November 2025 with a glyph-swapping web font and a malformed ZIP to hide malware.
The UAC-0050 ClickFix campaign used a fake reCAPTCHA to deploy the Lucky Volunteer infostealer against Ukrainian organizations, the Lampion banking trojan used the same ClickFix technique against Portuguese government and finance targets, a FileFix/search-ms variant delivered MetaStealer through a fake AnyDesk installer, and a fake ChatGPT download site combined SEO poisoning and malvertising to deliver cross-platform infostealers.
GootLoader has run a long campaign of SEO poisoning against legal services firms, a dual GootLoader and SocGholish campaign hit six law firms in 2023, and GootLoader returned after a seven-month hiatus in 2025 with glyph-swapped fonts and a malformed ZIP file.
North Korea ran the Contagious Interview campaign, using a fake job-assessment ClickFix lure to target the crypto industry with the same self-infection technique used against law firms and Ukrainian organizations.