logo

New ClickFix attacks abuse Windows App-V scripts to push malware

ID: d54c549d-ed64-5847-b46b-78f8fb30c176

STIX ID: report--d54c549d-ed64-5847-b46b-78f8fb30c176

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2026-01-26

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A ClickFix social-engineering campaign is delivering the Amatera infostealer by tricking victims into pasting a command that abuses the signed SyncAppvPublishingServer.vbs (App‑V) to launch PowerShell, perform anti-analysis checks, fetch base64 configuration from a public Google Calendar event, retrieve encrypted payloads hidden via LSB steganography in PNGs hosted on CDNs, and execute shellcode in memory; the report highlights the chain's use of living‑off‑the‑land binaries, WMI, and WinINet API calls and recommends restricting Run dialog access, removing unneeded App‑V components, and enabling PowerShell logging.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.