Tommy Madjar @ffforward.bsky.social · 20/06/2026It's one of the pre-built templates that the threat actor can choose from when they use the Clickfix-as-a-service ErrTraffic. And yeah they had a compromised account that was used to get their WordPress instance to inject it. 111
Tommy Madjar @ffforward.bsky.social · 20/06/2026Yeah it's fixed. However the #ErrTraffic affiliate had only MacOS and Windows configured as target OSes either way, so you wouldn't have seen it on Linux (Same reason it won't show on various URL scanners as default) 120
Tommy Madjar @ffforward.bsky.social · 20/06/2026Yeah, It's #ErrTraffic, inject in main response. It's a ClickFIx-as-a-Service, this affiliate has a Windows Payload that leads to NetSupport, and the broken Mac one. 000
Tommy Madjar @ffforward.bsky.social · 20/06/2026Heads up, Gizmodo has been compromised by some #ErrTraffic #ClickFix -as-a-Service affiliate. 040
Tommy Madjar @ffforward.bsky.social · 20/06/2026Yes, this is ErrTraffic (ClickFix-as-a-Service), inject is in main response. 050
Tommy Madjar @ffforward.bsky.social · 19/02/2026Would you run AdobeReader.exe from a days-old company called "TrustConnect Software PTY LTD" because they managed to purchase an Extended Validation certificate? Blog w. @selenalarson.bsky.social and @proofpoint.com @threatinsight.proofpoint.com team out now! www.proofpoint.com/us/blog/thre... 010
Tommy Madjar @ffforward.bsky.social · 19/05/2025This article that starts getting traction claims that the official RVTools website was distributing a malicious installer leading to Bumblebee. I see zero evidence of this actually being the case. 1/2 111
Tommy Madjar @ffforward.bsky.social · 18/11/2024New blog drop with @selenalarson.bsky.social and the rest of the team. This one covers a lot of threats using the #ClickFix technique to lure targets to infect themselves by pasting malicious CMD/PS code. My "fave" is the chumbox #malvertising on major tech sites. www.proofpoint.com/us/blog/thre... 0104