
Ukraine’s government incident response team describes a ClickFix campaign served from more than a hundred compromised sites and steered through a smart contract. One of its three installation chains loads a vulnerable AMD driver whose sample does not appear in the April 2026 copy of the Microsoft blocklist examined here.














