logo

Threat Actors Abuse Trusted Business Infrastructure to Host Infostealers

ID: 33f6ac41-4dba-54fe-a36b-dc94f212a658

STIX ID: report--33f6ac41-4dba-54fe-a36b-dc94f212a658

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-01-05

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Hudson Rock and ClickFix Hunter research exposes the "ClickFix" campaign, which tricks users into pasting and executing scripts via the Windows Run dialog to load infostealers (Lumma, Vidar, Stealc) directly into memory; compromised legitimate business websites (≈1,635 domains, ~220 with leaked credentials) are being weaponized as distribution infrastructure, creating an "Ouroboros" feedback loop that complicates takedowns and amplifies infection scale — mitigation should prioritize credential protection, remediating compromised sites, and context-aware detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.