Australia’s warning on ClickFix attacks distributing Vidar Stealer is an important reminder that social engineering is becoming more direct and dangerous. According to public reporting, the Australian Cyber Security Centre has observed ClickFix activity using compromised WordPress-hosted infrastructure to push Vidar Stealer malware. Users are shown fake Cloudflare verification or CAPTCHA prompts and are tricked into copying and executing malicious PowerShell commands themselves.
This technique is especially risky because it bypasses the usual “download and run this file” pattern. Instead, the user is manipulated into becoming part of the execution chain. Vidar Stealer is designed to steal sensitive information such as browser data, saved credentials, cryptocurrency wallet information, and system details.
We urge users and organizations to treat any website that asks them to copy, paste, or run commands in PowerShell, Command Prompt, Terminal, or Run dialog as highly suspicious. CAPTCHA or browser verification should never require users to execute system commands. That is not verification. That is malware installation with extra paperwork.
Organizations should strengthen DNS and web filtering, block malicious or newly observed domains, restrict PowerShell abuse where possible, monitor unusual outbound connections, and educate users to report suspicious prompts immediately. Security teams should also review endpoint logs for unexpected PowerShell activity and credential-stealing behavior.
The Australian Cyber Security Center (ACSC) is warning organizations of an ongoing malware campaign using the ClickFix social engineering technique to distribute the Vidar Stealer info-stealing malware. [...]
Source: Australia warns of ClickFix attacks pushing Vidar Stealer malware via Bleeping Computer — published 07 May 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.