ClickFix campaign abuses Deno runtime for infostealer delivery
ID: b5a998f1-9fb0-55ca-9d50-5a06b7e44ef3
STIX ID: report--b5a998f1-9fb0-55ca-9d50-5a06b7e44ef3
Feed Name: Sophos Blogs
CTU researchers investigated a June 2026 ClickFix campaign in which over 500 compromised WordPress sites delivered Cloudflare-themed lures that convinced users to run a PowerShell command; an MSI installer then used winget to install the legitimately signed Deno runtime, which fetched remote JavaScript to orchestrate follow-on activity including a Python infostealer, system reconnaissance, and persistence via registry Run keys and scheduled tasks, with identified C2 domains and an IP address provided as indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
