Rising ClickFix malware distribution trick puts PowerShell IT policies on notice
ID: f916a27d-dc3d-5cda-a9f3-70d87dc8a601
STIX ID: report--f916a27d-dc3d-5cda-a9f3-70d87dc8a601
Feed Name: Proofpoint Blog
Threat Score
The report details active phishing campaigns that deliver encoded PowerShell via malicious HTML email attachments to install remote access trojans (NetSupport), loaders (Latrodectus), and tools like Brute Ratel C4. Techniques include password-protected .7z archives, embedded execution instructions, and social-engineering lures such as fake Word errors and CAPTCHA prompts to obtain initial access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
