PoC Archive PoC Archive

tag

Clipboard-Injection

  • N/A social-engineering HIGH

    ClickFix Social-Engineering Technique — Fortinet-Branded Multi-Stage Lure (Fake File-Access Page + Fake CAPTCHA + Clipboard Injection)

    This entry documents a second ClickFix-style social-engineering demo, distinct from other ClickFix variants in this archive: a multi-stage lure that opens with a Fortinet-branded fake "Secure File Access" page (index.html) requesting a work email, then…

    Unverified 2026-07-27
  • N/A social-engineering HIGH

    ClickFix Social Engineering Technique — Fake Cloudflare Turnstile Just a Moment Verification Lure

    ClickFix is a widely reported in-the-wild social-engineering technique in which a fake CAPTCHA or "verification" page tricks a victim into copying an attacker-controlled command (silently injected into the clipboard by the page) and pasting/executing it…

    Unverified 2026-07-27
  • N/A social-engineering HIGH

    ClickFix Fake-CAPTCHA Social-Engineering Kit with IP Fencing and 19-Language Localization

    This is a fork of 0x204/ClickFix-Turnstile that adds two enhancements: real IP allow/block fencing at the Cloudflare Worker edge (checking the cf-connecting-ip request header against a hardcoded ALLOWEDIPS[] array before serving content), and genuine…

    Unverified 2026-07-27
  • N/A social-engineering HIGH

    ClickFix Fake reCAPTCHA to mshta/HTA Execution Chain

    This is a reference implementation of ClickFix, a widely used real-world social-engineering technique (reported by Unit42, Huntress, and Orange CyberDefense as used by numerous threat actors since roughly 2024, including in LummaStealer and Emmenhtal malware…

    Unverified 2026-07-27