logo

That PowerShell 'fix' for your root cert 'problem' is a malware loader in disguise

ID: 622040ef-acce-5958-a23d-1411510883c4

STIX ID: report--622040ef-acce-5958-a23d-1411510883c4

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2024-06-19

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Proofpoint reported multiple active criminal campaigns (TA571, ClearFix, ClearFake) using fake Chrome/Word/OneDrive error pop-ups and clipboard-based PowerShell instructions—sometimes delivered via blockchain-hosted scripts (EtherHiding)—to trick users into running commands that download loaders and stealers (Lumma, Vidar, Amadey, JaskaGo, etc.) and can lead to ransomware; campaigns have involved large-scale phishing and remain active.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.