logo

A Wretch Client: From ClickFix deception to information stealer deployment

ID: 27d1ce67-7450-5e7e-918d-b55fb68f267b

STIX ID: report--27d1ce67-7450-5e7e-918d-b55fb68f267b

Feed Name: Elastic Security Labs

Threat Score
75/100

Date Published: 2025-06-18

Date Updated: 2026-04-27

...
...

**Elastic Security Labs** analyzed a ClickFix social-engineering campaign that coerces users into pasting malicious PowerShell to deploy the multi-stage GHOSTPULSE loader, which sideloads a DLL and ultimately loads an x86 .NET loader that reflectively loads ARECHCLIENT2 (SectopRAT) in memory; the report includes technical stage-by-stage analysis, IOCs (domains, many IPs, SHA-256 hashes), infrastructure attribution, and detection recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.