logo

New ClickFix Variant Uses Rundll32 and WebDAV to Evade PowerShell Detection

ID: 212400f8-ef3e-5520-8c19-b7406a6637db

STIX ID: report--212400f8-ef3e-5520-8c19-b7406a6637db

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-30

Date Updated: 2026-05-11

Author: Tushar Subhra Dutta

...
...

**Executive summary:** A new ClickFix variant is actively targeting Windows users by social-engineering victims to run a rundll32/WebDAV command that fetches a malicious DLL (verification.google) which loads the SkimokKeep loader; the attack minimizes disk artifacts by moving to in-memory execution, later invoking PowerShell and injecting into browser processes, includes anti-analysis measures, and provides IPs/domains and detection recommendations (monitor rundll32 with davclnt.dll/DavSetCookie, audit LOLBin usage, restrict WebDAV on port 80).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.