ClickFix Campaigns Targeting Windows and macOS

Insikt Group identified five distinct clusters using the ClickFix social engineering technique for initial access. These clusters impersonate various services like Intuit QuickBooks and Booking.com, demonstrating operational variance but similar core techniques. ClickFix manipulates victims into executing malicious commands within native system tools, bypassing traditional security controls. The methodology has become a standardized template for cybercriminals and APT groups. Campaigns target diverse sectors and use sophisticated obfuscation and living-off-the-land tactics. Defenders are advised to implement aggressive behavioral hardening and user awareness training to mitigate these threats.

Pulse ID: 69c458219c8e6f0a874e9161
Pulse Link: https://otx.alienvault.com/pulse/69c458219c8e6f0a874e9161
Pulse Author: AlienVault
Created: 2026-03-25 21:48:17

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#CyberSecurity #ICS #InfoSec #Mac #MacOS #OTX #OpenThreatExchange #RAT #SocialEngineering #Windows #bot #AlienVault

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange
#front #giant グダペスト吐き祭り - ポイズン雷花の小説 - pixiv

前線では大スズメバチがドブネズミを粉砕。堕天使ババヤが審判の種を蒔き、汚らわしい害獣を焼く。 狼はゾクの巣穴をハチの巣と化する。サイは汚れた自走式カボヤチャを火だるまと化する。 聖なる大地の空ではハヤブサがカラスを狩る。海ではマグロがクジラを焼き払う。 古代文明帝国の奥地ではコウ

pixiv
#sow #judgment Gudapest Spitting Festival - ポイズン雷花の小 - pixiv

On the front lines, giant hornets crush sewer rats. The fallen angel Babaya sows the seeds of judgment and burns filthy vermin. Wolves turn

pixiv
#Zok #beehive Фестиваль плювання в Гудапешті - ポイズン雷 - pixiv

На передовій гігантські шершні розчавлюють каналізаційних щурів. Падший ангел Бабая сіє насіння суду та спалює брудних паразитів. Вовк перет

pixiv
Nach Planungsmängeln und Planer-Insolvenz wird die Sanierung des Freibads Stockheide teurer - eine Wiedereröffnung im Jahr 2026 ist nicht mehr realistisch. #Dortmund #Nordstadt #Hoeschpark #Freizeit #Sport #Denkmalschutz #Freibad #Politik #Rat
https://www.nordstadtblogger.de/nach-planungsmaengeln-und-planer-insolvenz-wird-die-sanierung-des-freibads-stockheide-teurer/
Nach Planungsmängeln und Planer-Insolvenz wird die Sanierung des Freibads Stockheide teurer - Nordstadtblogger

Die Sanierung des Freibads Stockheide wird teurer. Über die vielschichtigen Gründe hat Sportdezernentin Frauke Füsers jetzt den Verwaltungsvorstand informiert. Der Rat der Stadt entscheidet im Mai über die Kostenerhöhung. Erneute Kostensteigerungen nach Planer-Insolvenz Im Jahr …

Nordstadtblogger

Malicious PyPI Package - LiteLLM Supply Chain Compromise

A malicious supply chain attack has been discovered in the Python Package Index package litellm version 1.82.8. The compromised package contains a malicious .pth file that executes automatically when the Python interpreter starts, without requiring explicit import. This file, located in site-packages/, exfiltrates sensitive information including environment variables, SSH keys, and cloud credentials to an attacker-controlled server. The payload is double base64-encoded to evade basic static analysis. PyPI administrators have quarantined the project to limit its spread. Users are advised to check for the malicious file, rotate all potentially exposed credentials, and audit their PyPI publishing process. The attack is attributed to TeamPCP and is actively exploited in the wild.

Pulse ID: 69c3bb2520934c9e0b4e5dca
Pulse Link: https://otx.alienvault.com/pulse/69c3bb2520934c9e0b4e5dca
Pulse Author: AlienVault
Created: 2026-03-25 10:38:29

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#Cloud #CyberSecurity #InfoSec #OTX #OpenThreatExchange #PyPI #Python #RAT #SSH #SupplyChain #Troll #bot #AlienVault

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange

Supply Chain Attack: Malicious PyPI Packages

TeamPCP has launched a supply chain attack targeting LiteLLM, an open-source Python library used in 36% of cloud environments. Malicious versions 1.82.7 and 1.82.8 were published on PyPI, employing sophisticated techniques for payload delivery and persistence. The compromised packages exploit Python's .pth mechanism for stealthy execution across any Python process. The malware collects sensitive data including API keys, cloud credentials, and CI/CD secrets, encrypting and exfiltrating them to attacker-controlled domains. This attack follows TeamPCP's previous compromises of Aqua Security's Trivy and Checkmarx tools, highlighting an ongoing campaign against the open-source ecosystem. The incident underscores the potential for widespread impact and the need for vigilance in software supply chain security.

Pulse ID: 69c3bb29c62248c6ffd0b50c
Pulse Link: https://otx.alienvault.com/pulse/69c3bb29c62248c6ffd0b50c
Pulse Author: AlienVault
Created: 2026-03-25 10:38:33

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#Cloud #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #PyPI #Python #RAT #RCE #SupplyChain #Troll #bot #AlienVault

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange
グダペスト吐き祭り|ポイズン雷花

前線では大スズメバチがドブネズミを粉砕。堕天使ババヤが審判の種を蒔き、汚らわしい害獣を焼く。 狼はゾクの巣穴をハチの巣と化する。サイは汚れた自走式カボヤチャを火だるまと化する。 聖なる大地の空ではハヤブサがカラスを狩る。海ではマグロがクジラを焼き払う。 古代文明帝国の奥地ではコウノトリが黒い生命液を焼き尽くす。鉄槌の槍は心経網の中枢を吹き飛ばす。 前線後方では天罰の槍が花火要塞を焚き火地獄へ誘う。プリリン帝国の敗北は目前。 そんな中古代プリン生命体は又しても悪足掻きに走る。和平交渉と云う名のグタグタペスト吐き大会です。 プリン皇帝とそのキャラメルソースで有る没落花札辺境伯、現白米国の大

note(ノート)
Gudapest Spitting Festival|ポイズン雷花

On the front lines, giant hornets crush sewer rats. The fallen angel Babaya sows the seeds of judgment and burns filthy vermin. Wolves turn Zok dens into beehives. Rhinos set filthy self-propelled pumpkins on fire. In the skies of the sacred earth, falcons hunt crows. In the sea, tuna burn whale

note(ノート)