Skip to main content

PhishEye Blog

Threat research, takedown playbooks, and the operator’s view

Field notes on phishing detection, typosquat enforcement, search-threat strategy, and the takedown metrics that actually reduce customer harm — not vanity dashboards.

Recent research

Latest posts

ClickFix Drops Atomic Stealer via Fake DirBuster — PhishEye blog cover illustration

Research · · 10 min read

ClickFix Drops Atomic Stealer via Fake DirBuster

A fake DirBuster 'GitHub' page weaponized ClickFix clipboard hijacking to run a base64/zsh one-liner that installs Atomic Stealer (AMOS) on macOS — no exploit, just copy-and-paste. Analysis, IoCs, and defenses.

Read more

Stay close to the research

Subscribe to the RSS feed for new posts, or get in touch with the team behind the investigations.