ClickFix attack uses fake Windows Update screen to push malware
ID: 8f573373-fd76-52a9-8265-c8a6813b85db
STIX ID: report--8f573373-fd76-52a9-8265-c8a6813b85db
Feed Name: Bleeping Computer
ClickFix campaigns lure victims with realistic full-screen fake Windows Update or human-verification pages that paste malicious commands into the clipboard; attackers then use mshta, PowerShell, and a .NET Stego Loader to extract AES-encrypted shellcode embedded via PNG steganography, ultimately delivering LummaC2 and Rhadamanthys infostealers. Variants show advanced evasion (trampoline call chains, Donut in-memory loading) and widespread adoption; Huntress recommends disabling the Run box and monitoring for mshta/PowerShell process chains and RunMRU artifacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
