logo

New ClickFix Campaign Uses Cmdkey and Regsvr32 To Evade Detection

ID: 1f3043d9-6d93-5ea4-9a82-1e9d2aec9c59

STIX ID: report--1f3043d9-6d93-5ea4-9a82-1e9d2aec9c59

Feed Name: Cyber Press

Threat Score
72/100

Date Published: 2026-04-28

Date Updated: 2026-05-22

Author: Varshini

...
...

**ClickFix Evades Detection Tools:** CyberProof researchers describe a stealthy ClickFix campaign that uses a social-engineered Run dialog paste to execute chained cmd.exe commands which leverage native utilities (cmdkey to store credentials, regsvr32 to load a remote DLL via UNC) and establish persistence by creating a scheduled task that pulls its configuration from a remote XML, enabling fileless updates and evasive long-term access; the report provides behavioral detection and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.