logo

New ClickFix Attack Wave Targets Windows Systems to Deploy StealC Stealer

ID: 2dc07650-9db2-536c-92dc-b10adc7c4c7c

STIX ID: report--2dc07650-9db2-536c-92dc-b10adc7c4c7c

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-02-13

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A ClickFix campaign compromises websites to serve fake Cloudflare-style CAPTCHA pages that socially engineer Windows users into pasting and running a PowerShell command; the command loads Donut-generated shellcode in memory, which reflectively loads a 64-bit downloader that injects the StealC information stealer into legitimate processes. StealC harvests browser credentials, crypto wallets, Steam and email data, and exfiltrates to C2 servers; the report includes technical details of the fileless chain, TTPs, and multiple IOCs (IPs and URLs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.