ClickFix Is Now Hiring: From Job Platform Impersonation to Python-Based RAT Delivery
ID: 9a4d4249-fa6b-5639-82e4-b82953753d90
STIX ID: report--9a4d4249-fa6b-5639-82e4-b82953753d90
Feed Name: LevelBlue SpiderLabs Blog
This report analyzes the ClickFix phishing campaign that uses typosquatted job/professional networking sites and fake CAPTCHA prompts to trick victims into executing a multi-stage chain that abuses the Finger protocol, LOLBins (e.g., curl.exe), and portable Python runtimes to perform fileless, in-memory shellcode execution; the chain culminates in deploying CastleLoader (a ChaCha20/RC4-encrypted MaaS) and a Python-based RAT with WebSocket C2, persistence, interactive shell capabilities, and extensive IOCs and domains for detection and blocking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
