logo

How ClickFix Opens the Door to Stealthy StealC Information Stealer

ID: d616efb2-cec2-5330-8087-505ea5adc16f

STIX ID: report--d616efb2-cec2-5330-8087-505ea5adc16f

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
75/100

Date Published: 2026-02-12

Date Updated: 2026-04-28

Author: Rodel Mendrez

...
...

This report analyzes a multi-stage cybercrime campaign that deploys the StealC infostealer via a ClickFix fake CAPTCHA social-engineering lure; the chain runs PowerShell → Donut position-independent shellcode → reflective PE downloader → process-injected StealC, which exfiltrates browser credentials, wallets, Steam/Outlook accounts, system fingerprints and screenshots to RC4+Base64-encrypted C2 endpoints. The analysis includes technical details, IOCs (IPs, URLs, hashes), detection recommendations, and a Python decryption tool for captured C2 traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.