logo

ClickFix Is Now Hiring: From Job Platform Impersonation to Python-Based RAT Delivery

ID: 9a4d4249-fa6b-5639-82e4-b82953753d90

STIX ID: report--9a4d4249-fa6b-5639-82e4-b82953753d90

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
75/100

Date Published: 2026-06-04

Date Updated: 2026-06-05

Author: King Orande and Cris Tomboc

...
...

This report analyzes the ClickFix phishing campaign that uses typosquatted job/professional networking sites and fake CAPTCHA prompts to trick victims into executing a multi-stage chain that abuses the Finger protocol, LOLBins (e.g., curl.exe), and portable Python runtimes to perform fileless, in-memory shellcode execution; the chain culminates in deploying CastleLoader (a ChaCha20/RC4-encrypted MaaS) and a Python-based RAT with WebSocket C2, persistence, interactive shell capabilities, and extensive IOCs and domains for detection and blocking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.