The “Windows + R” Trap: ClickFix Scam Tricks Users into Installing StealC Malware
ID: 861fc216-784c-5e65-8467-8c7320b1e473
STIX ID: report--861fc216-784c-5e65-8467-8c7320b1e473
Feed Name: securityonline.info
LevelBlue describes a sophisticated multi-stage, fileless malware campaign that uses a "ClickFix" social-engineering prompt (a fake CAPTCHA) to trick victims into pasting a PowerShell command which loads Donut-generated shellcode and injects the StealC information stealer into svchost.exe; StealC harvests browser data, crypto-wallet secrets, system info, and exfiltrates it via RC4-encrypted HTTP. The report highlights the campaign's use of reflective memory-only loading, process injection, and encrypted C2 traffic, and recommends security awareness training to mitigate fake CAPTCHA/verification prompts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
