ClickFix Attack Replaces PowerShell With Cmdkey and Remote Regsvr32 Payload Delivery
ID: 9961009f-4750-5211-a008-df8195c53ccb
STIX ID: report--9961009f-4750-5211-a008-df8195c53ccb
Feed Name: cybersecurityNews.com
A new ClickFix variant observed in the wild uses social engineering (a fake CAPTCHA) to trick users into pasting a single Run-dialog command that chains cmdkey and regsvr32 to store credentials, load a remote DLL via SMB/UNC (\151.245.195.142\hi\demo.dll), and trigger a scheduled task that pulls a remote XML for second-stage payloads, enabling stealthy, persistent remote execution; defenders should monitor cmdkey and regsvr32 activity, restrict or monitor SMB/UNC outbound access, and review Task Scheduler entries referencing remote files. IOCs include IP 151.245.195.142 and SHA256:b2d9a99de44a7cd8faf396d0482268369d14a315edaf18a36fa273ffd5500108.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
