logo

ClickFix and CORNFLAKE.V3: Mandiant Uncovers a New Wave of Access-as-a-Service Campaigns

ID: 2eb34031-e1b2-55ad-917a-d7241a68b372

STIX ID: report--2eb34031-e1b2-55ad-917a-d7241a68b372

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2025-08-22

Date Updated: 2026-04-22

Author: Ddos

...
...

Mandiant attributes a coordinated cybercrime campaign to UNC5518 that weaponizes compromised websites with fake CAPTCHA “ClickFix” lures to trick victims into running downloader commands; this enables deployment of the CORNFLAKE.V3 backdoor (Node.js and PHP variants) and other payloads by partnering groups, with capabilities including persistence, multi-format payload execution, reconnaissance, Kerberoasting for credential theft, and use of access-as-a-service to monetize footholds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.