logo

From Victim to Vector: How Infostealers Turn Legitimate Businesses into Malware Hosts

ID: 9c25c74b-b83f-598c-b701-d28f3d52c090

STIX ID: report--9c25c74b-b83f-598c-b701-d28f3d52c090

Feed Name: infostealers.com

Threat Score
75/100

Date Published: 2025-12-30

Date Updated: 2026-06-07

Author: InfoStealers

...
...

Hudson Rock's report exposes the ClickFix campaign: a clipboard-based social-engineering attack that coerces users to paste PowerShell commands (via Windows+R, Ctrl+V, Enter) to fetch infostealers, and demonstrates a self-sustaining "victim-to-vector" feedback loop where stolen admin credentials from infected machines are used to compromise legitimate websites (220 domains correlated) to host further campaigns; the report includes technical anatomy, case studies (jrqsistemas.com, wo.cementah.com), and API endpoints for detection and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.