Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

ClickFix Campaign Exploits Fake LinkedIn VCs to Spread Malware Among Crypto and Web3 Experts

## Malware Campaign Targeting Cryptocurrency and Web3 Professionals

Malware Campaign Targeting Cryptocurrency and Web3 Professionals

A sophisticated malware campaign has been identified, targeting professionals in cryptocurrency and Web3 through fraudulent venture capital identities on LinkedIn. The operation utilizes advanced social engineering tactics, cross-platform payloads, and a fake CAPTCHA flow to deceive users into executing malicious commands.

Attackers impersonate executives from fictitious firms like SolidBit Capital, MegaBit, and Lumax Capital, using well-crafted LinkedIn profiles and personalized outreach messages. They engage with community leaders, project contributors, and founders, steering conversations toward scheduling a "funding" or "partnership" meeting. Victims are directed to Calendly pages that link to fake Zoom or Google Meet URLs hosted on attacker-controlled domains.

Technical Details of the ClickFix Campaign

The campaign uses a cloned conference or industry news page with a fake Cloudflare CAPTCHA overlay to deceive targets. The ClickFix process consists of three main steps:

Fake CAPTCHA: A seemingly legitimate bot check using a single checkbox. Clipboard Poisoning: JavaScript inserts an OS-specific command into the user's clipboard, either a PowerShell or bash command based on the User-Agent. Guided Terminal Execution: Users are instructed to paste the command into a terminal, reinforced by a countdown timer and animations.

The campaign employs a fileless loader model, allowing attackers to deploy additional malware without leaving detectable traces on disk. On Windows, a hidden PowerShell command executes a remote script, while on macOS, a multi-stage bash chain downloads and runs a Python payload. Both systems utilize obfuscated binaries to evade detection.

The campaign shows similarities with operations attributed to UNC1069, a financially motivated group linked to North Korea. These include the use of Zoom-lookalike domains, social engineering tactics on LinkedIn, and OS-specific command chains. However, definitive attribution remains unconfirmed.

They engage with community leaders, project contributors, and founders, steering conversations toward scheduling a "funding" or "partnership" meeting.
Stephen Gale · Thehackingpost

Professionals are advised to exercise caution with unsolicited investment offers and verify all aspects of potential partners. Key recommendations include:

Domain and Company Verification: Check registration dates and cross-reference team members for inconsistencies. Meeting Logistics Scrutiny: Use URL scanners and be wary of suspicious meeting links. Terminal Instructions Caution: Legitimate entities will not request terminal command execution for verification. Awareness of Urgency Tactics: Be cautious of pressure to act quickly or bypass standard procedures.

Type Value Context

Domain zoom[.]us07-web[.]us Fake Zoom page, hosts ClickFix payload

Domain zoom[.]07usweb[.]us Fake Zoom page, hosts MegaBit fake company site

Advertisement

Domain goog1e[.]us-meet[.]com Fake Google Meet page

Domain hedgeweeks[.]online C2 server; typosquat of Hedgeweek (hedgeweek.com)

Domain lumax[.]capital New campaign infrastructure

URL calendly[.]com/hureivemykhail/with-solidbit-meeting Calendly link used in social engineering

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories