Sign in

Tommy Madjar

@ffforward.bsky.social
444 followers 65 following 11 posts

Threat Researcher @ Proofpoint. Opinions are my own etc

PostsRepliesMedia
Tommy Madjar @ffforward.bsky.social · 20/06/2026
It's one of the pre-built templates that the threat actor can choose from when they use the Clickfix-as-a-service ErrTraffic. And yeah they had a compromised account that was used to get their WordPress instance to inject it.
111
Tommy Madjar @ffforward.bsky.social · 20/06/2026
Yeah it's fixed. However the #ErrTraffic affiliate had only MacOS and Windows configured as target OSes either way, so you wouldn't have seen it on Linux (Same reason it won't show on various URL scanners as default)
120
Tommy Madjar @ffforward.bsky.social · 20/06/2026
Yeah, It's #ErrTraffic, inject in main response. It's a ClickFIx-as-a-Service, this affiliate has a Windows Payload that leads to NetSupport, and the broken Mac one.
000
Tommy Madjar @ffforward.bsky.social · 20/06/2026
Heads up, Gizmodo has been compromised by some #ErrTraffic #ClickFix -as-a-Service affiliate.
040
Tommy Madjar @ffforward.bsky.social · 20/06/2026
Yes, this is ErrTraffic (ClickFix-as-a-Service), inject is in main response.
050
Tommy Madjar @ffforward.bsky.social · 19/02/2026
Would you run AdobeReader.exe from a days-old company called "TrustConnect Software PTY LTD" because they managed to purchase an Extended Validation certificate? Blog w. @selenalarson.bsky.social and @proofpoint.com @threatinsight.proofpoint.com team out now! www.proofpoint.com/us/blog/thre...
010
Tommy Madjar @ffforward.bsky.social · 19/05/2025
This article that starts getting traction claims that the official RVTools website was distributing a malicious installer leading to Bumblebee. I see zero evidence of this actually being the case. 1/2
111
Tommy Madjar @ffforward.bsky.social · 18/11/2024
New blog drop with @selenalarson.bsky.social and the rest of the team. This one covers a lot of threats using the #ClickFix technique to lure targets to infect themselves by pasting malicious CMD/PS code. My "fave" is the chumbox #malvertising on major tech sites. www.proofpoint.com/us/blog/thre...
0104