logo

Kimusky Hackers Leverage ClickFix Method to Deploy Malicious Scripts on Target Systems

ID: d0337d17-040a-5be8-ba4b-edc6340da3ae

STIX ID: report--d0337d17-040a-5be8-ba4b-edc6340da3ae

Feed Name: Cyber Press

Threat Score
88/100

Date Published: 2025-07-01

Date Updated: 2026-04-13

Author: Mandvi

...
...

Genians Security Center reports a sophisticated Kimsuky campaign using the "ClickFix" social-engineering technique to coerce victims into running obfuscated PowerShell or script commands that deploy multi-stage payloads (including RATs such as QuasarRAT), establish persistence, and exfiltrate data; the report provides extensive IoCs (MD5s, domains, IPs), infrastructure and linguistic attribution to North Korea, and recommends EDR behavioral detection and security awareness to mitigate the threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.