ClickFix Evades PowerShell Detection via Rundll32 and WebDAV
ID: e2be8cc0-030b-5426-9a8e-618a05433277
STIX ID: report--e2be8cc0-030b-5426-9a8e-618a05433277
Feed Name: GBHackers
Threat Score
A ClickFix variant abuses Windows rundll32.exe and the WebDAV mini-redirector to load remote DLLs via the Win+R social engineering flow, then transitions to PowerShell to deploy an in-memory loader called SkimokKeep that uses dynamic API resolution, process injection, anti-VM/sandbox and anti-debug techniques; the report includes observable rundll32 command-line and network indicators and suggests KQL hunting queries and telemetry to detect the activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
