logo

ClickFix Evades PowerShell Detection via Rundll32 and WebDAV

ID: e2be8cc0-030b-5426-9a8e-618a05433277

STIX ID: report--e2be8cc0-030b-5426-9a8e-618a05433277

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2026-03-30

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A ClickFix variant abuses Windows rundll32.exe and the WebDAV mini-redirector to load remote DLLs via the Win+R social engineering flow, then transitions to PowerShell to deploy an in-memory loader called SkimokKeep that uses dynamic API resolution, process injection, anti-VM/sandbox and anti-debug techniques; the report includes observable rundll32 command-line and network indicators and suggests KQL hunting queries and telemetry to detect the activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.