logo

Rising ClickFix malware distribution trick puts PowerShell IT policies on notice

ID: f916a27d-dc3d-5cda-a9f3-70d87dc8a601

STIX ID: report--f916a27d-dc3d-5cda-a9f3-70d87dc8a601

Feed Name: Proofpoint Blog

Threat Score
70/100

Date Published: 2024-11-21

Date Updated: 2026-04-28

...
...

The report details active phishing campaigns that deliver encoded PowerShell via malicious HTML email attachments to install remote access trojans (NetSupport), loaders (Latrodectus), and tools like Brute Ratel C4. Techniques include password-protected .7z archives, embedded execution instructions, and social-engineering lures such as fake Word errors and CAPTCHA prompts to obtain initial access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.