logo

Hackers Using ClickFix Technique to Hide Images within the Image Files

ID: e63d1011-c951-540b-9bb8-cad9f9de5cf8

STIX ID: report--e63d1011-c951-540b-9bb8-cad9f9de5cf8

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-12-23

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Huntress researchers uncovered the ClickFix campaign that uses convincing fake verification or Windows Update screens to get victims to run a command via Win+R; a PowerShell/.NET steganographic loader then extracts XOR-encrypted shellcode from PNG pixel data (red channel) and reflectively loads Donut-packed payloads, delivering information-stealing malware such as LummaC2 and Rhadamanthys. The technique emphasizes detection evasion by hiding payloads inside image pixels and using in-memory execution; mitigations include user awareness training and disabling the Run box via Group Policy or registry changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.