ClickFix: The new threat in cyberspace

ESET has published its latest Threat Report, which summarizes trends in the cyberthreat landscape, as observed through ESET telemetry from December 2024 to May 2025, as well as observations from the company's experts.hacker code

One of the most striking developments during this period was the emergence of ClickFix, a new deceptive attack vector, whose activity skyrocketed by more than 500% compared to the second half of 2024. This makes it one of the fastest growing threats, accounting for almost 8% of all blocked attacks in the first half of 2025. Now, ClickFix is ​​the second most common attack vector after phishing.

See more articles from iGuRu.gr when you search for news on Google.

ClickFix attacks display a fake error that tricks the victim into copying, pasting, and executing malicious commands on their device. This attack vector affects all major operating systems, including Windows, Linux, and macOS.

“The list of threats posed by ClickFix attacks is growing daily, including infostealers, ransomware, remote access trojans, cryptominers, post-exploitation tools, and even custom malware from state-linked threat actors,” says Jiří Kropáč, Director of Threat Prevention Labs at ESET.

The infostealer landscape also saw significant changes. With Agent Tesla losing its lead, SnakeStealer (also known as Snake Keylogger) rose to the top spot, becoming the most detectable infostealer in ESET telemetry. Its capabilities include logging keystrokes, stealing stored credentials, taking screenshots, and collecting clipboard data.

Meanwhile, ESET contributed to significant operations to neutralize Lumma Stealer and Danabot, two malware-as-a-service threats . Prior to the operation, Lumma Stealer activity in the first half of 2025 increased by 21% compared to the second half of 2024, while Danabot showed an even greater increase of 52%. These figures indicate that these were particularly significant threats, which makes their neutralization even more important.

The ransomware situation has further deteriorated, with rival gangs feuding. Annual data from 2024 shows that while ransomware attacks and the number of active gangs increased, ransom payments fell significantly. This difference is attributed to both law enforcement crackdowns and internal conflicts that disrupted the ransomware sector in 2024, but may also be related to reduced confidence in the gangs’ ability to deliver on their promises.

In the case of Android , adware detections increased by 160%, mainly due to a new, sophisticated threat called Kaleidoscope. This malware uses a deceptive “evil tween” strategy to distribute apps that bombard users with annoying ads, negatively impacting the performance of their devices.

At the same time, NFC-based scams increased more than thirty-five-fold, fueled by phishing campaigns and ingenious relaying techniques. While the absolute numbers remain low, the explosive growth highlights the rapid evolution of cybercriminal methods and their focus on exploiting NFC technology.

ESET’s GhostTap research shows how the malware steals card details, allowing attackers to load victims’ cards into their own digital wallets and use their phones for contactless, illicit payments worldwide. Organized fraud groups use multiple devices to expand these attacks.

SuperCard X integrates NFC theft into a simple and minimalist malware-as-a-service tool. It presents itself as a harmless NFC-related application, but once installed on a victim’s device, it silently captures and transmits card data in real time to make quick payments.

“From innovative social engineering techniques to sophisticated mobile threats and significant disruptions from information theft programs, the threat landscape in the first half of 2025 was very interesting,” adds Kropáč regarding the content of ESET’s latest Threat Report.

For more information, you can read the ESET Threat Report for the second half of 2024 on WeLiveSecurity.com.


Google preferences

Leave a Comment

Your email address will not be published. Required fields are marked *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).