A Wretch Client: From ClickFix deception to information stealer deployment
ID: 27d1ce67-7450-5e7e-918d-b55fb68f267b
STIX ID: report--27d1ce67-7450-5e7e-918d-b55fb68f267b
Feed Name: Elastic Security Labs
Threat Score
**Elastic Security Labs** analyzed a ClickFix social-engineering campaign that coerces users into pasting malicious PowerShell to deploy the multi-stage GHOSTPULSE loader, which sideloads a DLL and ultimately loads an x86 .NET loader that reflectively loads ARECHCLIENT2 (SectopRAT) in memory; the report includes technical stage-by-stage analysis, IOCs (domains, many IPs, SHA-256 hashes), infrastructure attribution, and detection recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
