The Shadowserver Foundation

4 posts
Avatar

The Shadowserver Foundation

Verified account Aggregated content
@Shadowserver
Following
Followers
Posts
Replies
Highlights
Media
Likes
Avatar
The Shadowserver Foundation Verified account Aggregated content @Shadowserver · 8h

We added a feed of IPs/websites with ClickFix/ClearFake injected code in our Compromised Website reporting, tagged as 'clickfix'. Visitors of the website get tricked to install malware when injected JavaScript executes. If you receive an alert review for root cause of compromise! https://t.co/pQllnpPkLy -

Tweet Image
Avatar
The Shadowserver Foundation Verified account Aggregated content @Shadowserver · 8h

@Europol @MicrosoftDCU nCSIRT-only Tycoon 2FA Domains Special Report run 2026-03-04 (historical C2/panel/infra domains) link: https://t.co/DiQBcmjzLZ -

Avatar
The Shadowserver Foundation Verified account Aggregated content @Shadowserver · 8h

Compromised Website Report (now with ClickFix data!): https://t.co/D1KZAGvfTr Dashboard World Map view of infected IPs: https://t.co/czz0s9XsQp Dashboard Tree Map view of infected IPs: https://t.co/WMiAnd22O8 -

Avatar
The Shadowserver Foundation Verified account Aggregated content @Shadowserver · 8h

657 instances shared for 2026-03-14. We expect to increase the volume of the feed in the future! We would like to thank our Alliance partners and @ValidinLLC for the collaboration making this possible! Background on investigating ClickFix/ClearFake: https://t.co/UY8NFEKr1C -