Meet IClickFix: a widespread framework using the ClickFix tactic
ID: b1e3dd05-2c2c-5813-832c-55a1ccbdf166
STIX ID: report--b1e3dd05-2c2c-5813-832c-55a1ccbdf166
Feed Name: Sekoia.com
This report details the IClickFix campaign (active since late 2024), where attackers compromised over 3,800 WordPress sites to inject an obfuscated JavaScript framework that replaces pages with a ClickFix (fake CAPTCHA) lure; victims who execute the provided command download and run obfuscated PowerShell droppers that deploy NetSupport RAT (and previously Emmenhtal Loader/XFiles Stealer). The analysis includes infection chain stages, YARA rules, IoCs (domains, IPs, file hashes), evidence of YOURLS abused as a TDS, and recommendations for monitoring and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
