logo

Hackers Use ClickFix Prompt to Install MSI Package and Launch Hands-On-Keyboard Attack

ID: 436d82fe-26d7-5897-80a1-531164c1179b

STIX ID: report--436d82fe-26d7-5897-80a1-531164c1179b

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Tushar Subhra Dutta

...
...

Huntress reported a ClickFix social-engineering campaign where a user was tricked into running a command that used pcalua.exe to proxy mshta and silently install an MSI, deploying a Potemkin loader that fetched RMMProject (memory-loaded RAT) and later EtherRAT; the operator performed hands-on-keyboard lateral movement across the network (WMIExec/SMBExec), disabled Windows Defender using AMSI/registry/service techniques, established Cloudflare tunnels and Chisel SOCKS persistence, and compromised over 11 hosts. The report includes detailed IoCs (hashes, IPs, domains, Ethereum contract/storage keys, file paths, registry keys) and recommends auditing endpoint coverage and blocking the Windows Run dialog and suspicious cloudflared binaries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.