logo

ClickFix Attack Replaces PowerShell With Cmdkey and Remote Regsvr32 Payload Delivery

ID: 9961009f-4750-5211-a008-df8195c53ccb

STIX ID: report--9961009f-4750-5211-a008-df8195c53ccb

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-27

Date Updated: 2026-04-27

Author: Tushar Subhra Dutta

...
...

A new ClickFix variant observed in the wild uses social engineering (a fake CAPTCHA) to trick users into pasting a single Run-dialog command that chains cmdkey and regsvr32 to store credentials, load a remote DLL via SMB/UNC (\151.245.195.142\hi\demo.dll), and trigger a scheduled task that pulls a remote XML for second-stage payloads, enabling stealthy, persistent remote execution; defenders should monitor cmdkey and regsvr32 activity, restrict or monitor SMB/UNC outbound access, and review Task Scheduler entries referencing remote files. IOCs include IP 151.245.195.142 and SHA256:b2d9a99de44a7cd8faf396d0482268369d14a315edaf18a36fa273ffd5500108.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.