logo

FileFix in the wild! New FileFix campaign goes beyond POC and leverages steganography

ID: fc5ef2d5-a5d6-5d0e-85dd-672905e52841

STIX ID: report--fc5ef2d5-a5d6-5d0e-85dd-672905e52841

Feed Name: TRU Security by Acronis

Threat Score
72/100

Date Published: 2025-09-16

Date Updated: 2026-07-24

...
...

**Executive summary:** Acronis TRU discovered an active, evolving FileFix/ClickFix phishing campaign that uses sophisticated obfuscation and steganography—embedding a second-stage PowerShell script and encrypted executables inside JPG images downloaded from benign-hosted locations—to deliver a Go-based loader which deploys the StealC infostealer targeting browsers, crypto wallets, messaging apps and cloud credentials; the report includes IoCs (hashes, IP 77.90.153.225, multiple domains), technical analysis, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.