Skip to main content

PhishEye Blog

Threat research, takedown playbooks, and the operator’s view

Field notes on phishing detection, typosquat enforcement, search-threat strategy, and the takedown metrics that actually reduce customer harm — not vanity dashboards.

Recent research

ClickFix 2026: Fake CAPTCHA Hides C2 On-Chain — PhishEye blog cover illustration

Research · · 15 min read

ClickFix 2026: Fake CAPTCHA Hides C2 On-Chain

A live ClickFix campaign poisons your clipboard via a fake CAPTCHA and hides its C2 on the Polygon blockchain (EtherHiding) to defeat takedowns. Full chain, 97-domain IOC feed, defenses.

Read more
Automate Phishing URL Reporting via APIs (2026) — PhishEye blog cover illustration

Cybersecurity · · 11 min read

Automate Phishing URL Reporting via APIs (2026)

Build a phishing-reporting pipeline with APIs: validate a URL, submit to Safe Browsing and urlscan, find host and registrar abuse contacts via RDAP, and escalate.

Read more
PrizeBuzz: The .buzz Prize-Scam Phishing Network — PhishEye blog cover illustration

Research · · 10 min read

PrizeBuzz: The .buzz Prize-Scam Phishing Network

PrizeBuzz runs one fake-prize-survey kit across 318 .buzz domains, cloning OMT, Coca-Cola, Vodafone and ~26 more brands over WhatsApp behind Cloudflare. IoCs inside.

Read more

Latest posts

ClickFix Drops Atomic Stealer via Fake DirBuster — PhishEye blog cover illustration

Research · · 10 min read

ClickFix Drops Atomic Stealer via Fake DirBuster

A fake DirBuster 'GitHub' page weaponized ClickFix clipboard hijacking to run a base64/zsh one-liner that installs Atomic Stealer (AMOS) on macOS — no exploit, just copy-and-paste. Analysis, IoCs, and defenses.

Read more

Stay close to the research

Subscribe to the RSS feed for new posts, or get in touch with the team behind the investigations.