Deconstructing a Cyber Deception: An Analysis of the Clickfix HijackLoader Phishing Campaign
ID: 715b3290-5834-5425-accf-1aaf8c4e0ca1
STIX ID: report--715b3290-5834-5425-accf-1aaf8c4e0ca1
Feed Name: Seqrite Blog
**Executive Summary:** This report analyzes HijackLoader, a Malware‑as‑a‑Service loader observed since late 2023 that uses CAPTCHA-based phishing pages, fake installers and malvertising to deliver a multi-stage PowerShell loader which employs heavy obfuscation, anti-VM/sandbox checks, process doppelgänging and direct WOW64 syscalls to unpack a protected .NET PE and load DLLs that fetch infostealer/RAT payloads; the report includes network and file IOCs, detection names, and MITRE ATT&CK mappings to aid detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
