logo

New ClickFix attack Hides in Native Windows Tools to Reduce Detection Risk

ID: 6400d7d3-56bc-5c3e-bc79-020675c9b747

STIX ID: report--6400d7d3-56bc-5c3e-bc79-020675c9b747

Feed Name: HackRead

Threat Score
70/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: Deeba Ahmed

...
...

CyberProof identified a ClickFix campaign where attackers socially engineer Windows users with fake CAPTCHA prompts to paste a Win+R command that uses LOLBins (cmdkey, regsvr32) to fetch a remote DLL (demo.dll) from 151.245.195.142, execute it via DllRegisterServer/CreateProcessA, and persist via a scheduled task named RunNotepadNow with remote task instructions in 777.xml; the campaign emphasizes stealth by avoiding PowerShell and using trusted Windows components.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.