logo

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist

ID: 17c434d3-2d17-55e5-9c63-985f749d3e32

STIX ID: report--17c434d3-2d17-55e5-9c63-985f749d3e32

Feed Name: infostealers.com

Threat Score
80/100

Date Published: 2026-07-14

Date Updated: 2026-07-15

Author: InfoStealers

...
...

Hudson Rock details a sophisticated campaign in which an infostealer obtained saved credentials from a developer who downloaded pirated software, allowing threat actors to compromise a high-traffic Artlist blog subdomain and inject obfuscated JavaScript that leverages a Polygon smart contract (EtherHiding) to dynamically resolve a ClickFix payload; the payload coerces users into executing a PowerShell chain that side-loads malicious DLLs via a signed updater, ultimately deploying a resilient RAT with hybrid encryption and Tor fallbacks. The report includes network and file IOCs (domains, IPs, .onion addresses, smart contract address, and SHA-256 hashes) and contextual analysis of the attack chain and mitigation feed capabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.