New ClickFix Variant Uses Rundll32 and WebDAV to Evade PowerShell Detection
ID: 212400f8-ef3e-5520-8c19-b7406a6637db
STIX ID: report--212400f8-ef3e-5520-8c19-b7406a6637db
Feed Name: cybersecurityNews.com
**Executive summary:** A new ClickFix variant is actively targeting Windows users by social-engineering victims to run a rundll32/WebDAV command that fetches a malicious DLL (verification.google) which loads the SkimokKeep loader; the attack minimizes disk artifacts by moving to in-memory execution, later invoking PowerShell and injecting into browser processes, includes anti-analysis measures, and provides IPs/domains and detection recommendations (monitor rundll32 with davclnt.dll/DavSetCookie, audit LOLBin usage, restrict WebDAV on port 80).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
