logo

Beware of the New ‘Executive Award’ Campaign That Uses ClickFix to Deliver Stealerium Malware

ID: 3caffa8f-6a27-50a4-998c-0a54e68f43ae

STIX ID: report--3caffa8f-6a27-50a4-998c-0a54e68f43ae

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-12-03

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A phishing campaign impersonating an "Executive Award" lures users to a fake HTML form to steal credentials, then delivers a malicious SVG that executes a PowerShell payload via the ClickFix chain to install the Stealerium infostealer; the malware persists, communicates with C2 servers at 31.57.147.77:6464, and uses multiple download endpoints. Organizations are advised to monitor for unusual PowerShell activity, suspicious SVG execution, and network connections to the identified infrastructure, and to block the known malicious IPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.