Social Engineering Examples

ClickFix & SEO Poisoning

ClickFix and SEO poisoning attacks get a victim to infect their own machine: a fake CAPTCHA or error message that walks them through pasting a malicious command into Windows Run, or a poisoned search result that ranks a booby-trapped download above the real one. This family includes the long-running Gootloader campaigns against law firms and several 2024-2026 fake-software and fake-job-interview schemes.


8 Cases
CA
Confirmed

UAC-0050 ClickFix Fake-reCAPTCHA Campaign Deploys 'Lucky Volunteer' Infostealer Against Ukrainian Organizations

A Ukrainian-language "shared document" phishing wave used a fake reCAPTCHA "verify you are human" ClickFix page to trick victims into pasting and running PowerShell themselves, deploying a rarely-seen infostealer Proofpoint dubbed suspected "Lucky Volunteer" in activity assessed to overlap with the Russia-linked espionage actor UAC-0050.

Incident 2024Read →
CA
Confirmed

Lampion Banking Trojan ClickFix Campaign vs Portuguese Government, Finance and Transport Sectors

A revived Lampion banking-trojan campaign spoofed Portugal's tax authority site to trick victims into pasting a PowerShell command into the Windows Run dialog, chaining through multiple obfuscated VBS stages before Unit 42 caught it with the final payload stage disabled.

Incident 2025Read →
CA
Confirmed

GootLoader SEO Poisoning of Legal Services Firms

GootLoader operators hijacked Google search rankings for legal-agreement phrases, luring law firm staff to fake forum "direct download" pages that delivered malicious JavaScript loaders, some of which escalated via Cobalt Strike into REvil ransomware attacks, a pattern CFC's Incident Response Team documented after seeing it hit multiple insured legal services firms.

Incident 2021Read →
CA
Confirmed

GootLoader and SocGholish Dual Campaign Against Six Law Firms (2023)

eSentire's Threat Response Unit blocked 10 separate attacks across six unnamed law firms in Jan-Feb 2023, foiling two parallel campaigns: SEO-poisoned fake "agreement" downloads delivering GootLoader, and a compromised Notary Public website serving a fake Chrome update to deliver SocGholish.

Incident 2023Read →
CA
Confirmed

Fake AnyDesk Installer to MetaStealer: FileFix/search-ms Variant of ClickFix

A victim searching for the AnyDesk remote-access tool hit a typosquatted site with a fake Cloudflare Turnstile that, instead of the usual ClickFix paste-and-run trick, abused the Windows search-ms protocol to pull a disguised LNK/PDF from an attacker SMB share, ultimately installing an MSI that fingerprinted the host and dropped the MetaStealer infostealer.

Incident 2025Read →
CA
Confirmed

Fake ChatGPT Download Site (openew[.]app): SEO Poisoning, Malvertising, and an AI-Generated chatgpt.com Redirect Deliver Cross-Platform Infostealers with Wallet-Swap Payload

A convincing fake ChatGPT download site, openew[.]app -- reached in part via an AI-generated fake outage page rendered on a real chatgpt.com/s/ URL -- used malvertising and SEO poisoning to push Windows visitors to a credential-stealing loader and Mac visitors to Odyssey Stealer (an AMOS/Atomic Stealer fork) that also swapped in trojanized Ledger and Trezor wallet apps.

Incident 2026Read →
CA
Confirmed

North Korea's 'Contagious Interview' ClickFix Fake Job-Assessment Campaign Targets Crypto Industry (2025)

Lazarus-linked operators built polished fake job-interview sites impersonating Coinbase, Kraken, Circle and other crypto firms, then used a fabricated camera-driver error to trick applicants into pasting a 'fix' command into their terminal, installing backdoors like GolangGhost and FrostyFerret.

Incident 2025Read →
CA
Confirmed

Gootloader Returns After 7-Month Hiatus: SEO Poisoning, Glyph-Swapped Fonts, and a Dual-Personality Malformed ZIP (2025)

After going quiet on March 31, 2025 following a researcher's disruption campaign, Gootloader returned on November 5, 2025 with a glyph-swapping WOFF2 web font to hide malicious filenames and a malformed ZIP archive that extracts a working JScript loader in Windows Explorer but a harmless decoy in 7-Zip, Python, or VirusTotal - spread across 100+ SEO-poisoned sites and thousands of keywords, feeding the Supper SOCKS5 backdoor and, via Storm-0494/Vanilla Tempest, ransomware deployment.

Incident 2025Read →