logo

New ClickFix Attack Wave Targeting Windows Systems to Deploy StealC Stealer

ID: cbeab211-4250-56fa-be38-f93e9e73ac43

STIX ID: report--cbeab211-4250-56fa-be38-f93e9e73ac43

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-02-13

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A sophisticated campaign uses compromised websites to display fake Cloudflare CAPTCHA pages that trick Windows users into running a PowerShell 'ClickFix' command; the chain downloads Donut-generated shellcode and a Visual C++ PE downloader which injects the StealC infostealer into svchost.exe to steal browser credentials, crypto wallet extensions, Steam and Outlook data. The attack uses fileless, in-memory execution, dual-layer string obfuscation, and RC4/Base64-encrypted C2 traffic; defenders should monitor for encoded PowerShell execution, unusual User-Agent strings (e.g., "Loader"), and API patterns indicating shellcode injection (VirtualAlloc/CreateThread).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.