<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Phishing on Saksham Anand</title>
    <link>/tags/phishing/</link>
    <description>Recent content in Phishing on Saksham Anand</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <lastBuildDate>Sun, 19 Apr 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="/tags/phishing/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>One Click(Fix) To Rule Them All, One Click(Fix) To Find Them</title>
      <link>/blog/clickfix-google-ads-discovery/</link>
      <pubDate>Sun, 19 Apr 2026 00:00:00 +0000</pubDate>
      <guid>/blog/clickfix-google-ads-discovery/</guid>
      <description>Almost a year after my last ClickFix post, ClickFix continues to be all the rage and remains a technique of choice for initial access among many threat actors. ClickFix has since evolved from solving CAPTCHA and error prompts to impersonating documentation for products such as Claude Code, Mac storage cleaning guides, and malicious instructions via Medium blogs, among many other lures. This post will look at how a single ClickFix domain can be used to help discover many others.</description>
    </item>
    <item>
      <title>A Game Of Probabilities | Discovering ClickFix Infrastructure</title>
      <link>/blog/clickfix-infrastructure-discovery/</link>
      <pubDate>Sun, 23 Mar 2025 00:00:00 +0000</pubDate>
      <guid>/blog/clickfix-infrastructure-discovery/</guid>
      <description>What is ClickFix? ClickFix is a social engineering technique increasingly being used by actors in the past few months. The technique relies on fooling users to run PowerShell or Terminal commands on their computers, through the use of fake error dialogue boxes. This post will look at how the domains involved in ClickFix script can be latched onto to discover additional infrastructure. The ClickFix script in this case was used to download the SectopRAT malware, you can read more about the malware itself on my friend Chris&amp;rsquo;s blog here.</description>
    </item>
  </channel>
</rss>
