From Victim to Vector: How Infostealers Turn Legitimate Businesses into Malware Hosts
ID: 9c25c74b-b83f-598c-b701-d28f3d52c090
STIX ID: report--9c25c74b-b83f-598c-b701-d28f3d52c090
Feed Name: infostealers.com
Hudson Rock's report exposes the ClickFix campaign: a clipboard-based social-engineering attack that coerces users to paste PowerShell commands (via Windows+R, Ctrl+V, Enter) to fetch infostealers, and demonstrates a self-sustaining "victim-to-vector" feedback loop where stolen admin credentials from infected machines are used to compromise legitimate websites (220 domains correlated) to host further campaigns; the report includes technical anatomy, case studies (jrqsistemas.com, wo.cementah.com), and API endpoints for detection and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
