
Fake Advisors, ClickFix, and Chrome Sync Spying
This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…
This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result “install guide,” a recruiter outreach, or a helpdesk phone call. The lures push victims to paste commands, install fake software, or reset MFA, leading to account takeover or malware installation.
This bulletin describes several distinct but related social engineering campaigns that all rely on the same core idea: trick people into trusting a familiar screen. In one case, sponsored Google search results led users to a fake Apple Support style install guide for Claude, hosted as a claude.ai/share conversation, which told them to open Terminal and paste a curl command. That command ultimately delivered MacSync Stealer. A second campaign used a ClickFix style lure on Windows, telling victims to press Win+R and paste a single command to fix an issue, which instead pulled a payload from a WebDAV endpoint and ran it filelessly via rundll32.exe. A third pattern involved vishing calls impersonating IT helpdesk staff, pressuring targets to approve an MFA reset or device re-enrollment, which opened the door to SSO account takeover.
Each lure exploits a moment where people expect help or a quick fix rather than a threat:
The common thread is that none of these techniques require exploiting a software vulnerability. They rely entirely on getting a person to take one small, seemingly reasonable action: pasting a command or approving a reset.
Organizations can reduce exposure to this pattern of attacks by reinforcing a few habits across the workforce. Employees should be trained to treat any command-paste instruction as a red flag and escalate to IT rather than comply. Software should only be installed from official vendor pages, not from search ads or shared chat links. Helpdesk and identity teams should require strong, out-of-band verification before approving MFA resets or device re-enrollment, since this step is the pivot point into SSO account takeover and downstream SaaS data theft. Given that healthcare, banking, financial services, manufacturing, retail, technology, and energy organizations are all named as affected, these controls apply broadly across sectors rather than to a single industry.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
ClickFix is a lure that tells a user to paste a single command into the Windows Run dialog to fix a supposed issue, which instead pulls a payload from a remote WebDAV share and runs it filelessly, leaving no artifacts on disk.
Attackers use sponsored Google search results to lead victims to a fake Apple Support style install guide for Claude, which instructs them to paste a curl command into Terminal, ultimately leading to MacSync Stealer.
Health-ISAC warns that vishing calls are used to trigger MFA resets or device re-enrollment, which can lead to SSO account takeover on platforms like Microsoft Entra, Okta, or Google, followed by rapid data theft from connected SaaS systems.
Employees should treat any instruction to paste a command into Terminal or Windows Run as high risk and escalate to IT or security for verification rather than following it.
You Google “how to install Claude on a Mac” and click the top Apple‑looking result, seems safe, right? That ad opens a fake Apple Support–style Claude guide on claude.ai/share. It tells you: open Terminal and paste this one curl command, behind the scenes, it drops MacSync Stealer on your Mac. Same trick on Windows: a “ClickFix” page says, “To fix this issue, press Win+R and paste the following command.” That single line quietly talks to a WebDAV share and runs malware with rundll32.exe, leaving almost nothing on disk. Aha moment: if any website or “support” guide tells you to paste a command into Terminal or Windows Run, stop. Take a screenshot and send it to IT or security before you touch a thing.

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

Researchers report an active phishing-as-a-service operation, Forg365, that targets Microsoft 365 users with document/payment-themed lures and techniques that…

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay…

The “Pink” data extortion group is running a real-world voice phishing campaign targeting employees in Microsoft 365 / Entra ID environments. Callers…

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites…

Attackers are taking over hotel and conference Wi‑Fi gateways and changing DNS settings so travelers are silently redirected to fake Microsoft 365 sign-in…