<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>social-engineering — PoC Archive</title><link>https://poc.intelseclab.com/pocs/social-engineering/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 27 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/pocs/social-engineering/index.xml" rel="self" type="application/rss+xml"/><item><title>ClickFix Social-Engineering Technique — Fortinet-Branded Multi-Stage Lure (Fake File-Access Page + Fake CAPTCHA + Clipboard Injection)</title><link>https://poc.intelseclab.com/pocs/social-engineering/2026-07-27_clickfix-fortinet-lure-multistage/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/social-engineering/2026-07-27_clickfix-fortinet-lure-multistage/</guid><description>High severity — social-engineering · N/A (social-engineering technique, not a software vulnerability). Status: PoC (inert placeholder payload). Affects: Human victims via a browser-rendered phishing lure; end effect targets Windows Run dialog / PowerShell. Tags: clickfix, fake-captcha, clipboard-injection, brand-impersonation, social-engineering, phishing, run-dialog, multistage-lure.</description><category>social-engineering</category><category>High</category><category>clickfix</category><category>fake-captcha</category><category>clipboard-injection</category><category>brand-impersonation</category><category>social-engineering</category><category>phishing</category><category>run-dialog</category><category>multistage-lure</category></item><item><title>ClickFix Social Engineering Technique — Fake Cloudflare Turnstile Just a Moment Verification Lure</title><link>https://poc.intelseclab.com/pocs/social-engineering/2026-07-27_clickfix-cloudflare-turnstile-lure/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/social-engineering/2026-07-27_clickfix-cloudflare-turnstile-lure/</guid><description>High severity — social-engineering · N/A (social-engineering technique, not a software vulnerability). Status: PoC (benign placeholder payload). Affects: Human victim / browser + Windows Run dialog (Win+R) — no software vulnerability, this is a social-engineering lure page. Tags: clickfix, fake-captcha, cloudflare-turnstile-lure, clipboard-injection, social-engineering, phishing, run-dialog, multilingual-lure.</description><category>social-engineering</category><category>High</category><category>clickfix</category><category>fake-captcha</category><category>cloudflare-turnstile-lure</category><category>clipboard-injection</category><category>social-engineering</category><category>phishing</category><category>run-dialog</category><category>multilingual-lure</category></item><item><title>ClickFix Fake-CAPTCHA Social-Engineering Kit with IP Fencing and 19-Language Localization</title><link>https://poc.intelseclab.com/pocs/social-engineering/2026-07-27_clickfix-fake-captcha-ip-fencing-i18n/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/social-engineering/2026-07-27_clickfix-fake-captcha-ip-fencing-i18n/</guid><description>High severity — social-engineering · N/A (social-engineering technique, not a software vulnerability). Status: PoC (benign placeholder payload). Affects: End users of Windows workstations (via Run dialog / PowerShell paste-and-execute); no vulnerable software component. Tags: clickfix, fake-captcha, clipboard-injection, ip-fencing, localization, social-engineering, phishing, run-dialog, cloudflare-worker.</description><category>social-engineering</category><category>High</category><category>clickfix</category><category>fake-captcha</category><category>clipboard-injection</category><category>ip-fencing</category><category>localization</category><category>social-engineering</category><category>phishing</category><category>run-dialog</category><category>cloudflare-worker</category></item><item><title>ClickFix Fake reCAPTCHA to mshta/HTA Execution Chain</title><link>https://poc.intelseclab.com/pocs/social-engineering/2026-07-27_clickfix-recaptcha-phish-mshta-hta/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/social-engineering/2026-07-27_clickfix-recaptcha-phish-mshta-hta/</guid><description>High severity — social-engineering · N/A (social-engineering technique, not a software vulnerability). Status: Weaponized (educational/benign demo payload). Affects: Human victim / Windows Run dialog (Win+R) or PowerShell/cmd, via mshta.exe. Tags: clickfix, fake-captcha, clipboard-injection, mshta, hta, social-engineering, phishing, run-dialog, recaptcha-impersonation.</description><category>social-engineering</category><category>High</category><category>clickfix</category><category>fake-captcha</category><category>clipboard-injection</category><category>mshta</category><category>hta</category><category>social-engineering</category><category>phishing</category><category>run-dialog</category><category>recaptcha-impersonation</category></item><item><title>Windows ShellLink (.lnk) Remote Code Execution — CVE-2026-21510 LNK-Stomping Generator</title><link>https://poc.intelseclab.com/pocs/social-engineering/2026-07-05_cve-2026-21510-lnk-stomping-generator/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/social-engineering/2026-07-05_cve-2026-21510-lnk-stomping-generator/</guid><description>High severity — social-engineering · CVE-2026-21510. Status: Weaponized. Affects: Windows Shell Link (.lnk) parsing (MS-SHLLINK). Tags: lnk-stomping, shelllink, cve-2026-21510, windows, initial-access, phishing, anti-forensics, red-team.</description><category>social-engineering</category><category>High</category><category>lnk-stomping</category><category>shelllink</category><category>cve-2026-21510</category><category>windows</category><category>initial-access</category><category>phishing</category><category>anti-forensics</category><category>red-team</category></item><item><title>RTF Protected-View Bypass (CVE-2026-21514) Chained with ShellLink RCE (CVE-2026-21510) — Builder Scripts</title><link>https://poc.intelseclab.com/pocs/social-engineering/2026-07-05_cve-2026-21514-cve-2026-21510-rtf-lnk-builder/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/social-engineering/2026-07-05_cve-2026-21514-cve-2026-21510-rtf-lnk-builder/</guid><description>High severity — social-engineering · CVE-2026-21514, CVE-2026-21510. Status: PoC. Affects: Microsoft Office (RTF/Word rendering + Protected View) and Windows Shell Link (.lnk) handling. Tags: rtf, lnk, ole-object, protected-view-bypass, cve-2026-21514, cve-2026-21510, phishing, initial-access.</description><category>social-engineering</category><category>High</category><category>rtf</category><category>lnk</category><category>ole-object</category><category>protected-view-bypass</category><category>cve-2026-21514</category><category>cve-2026-21510</category><category>phishing</category><category>initial-access</category></item></channel></rss>