ClickFix Gets Creative: Malware Buried in Images
ID: 9cf0c013-bd0d-5789-b783-99624e0f2427
STIX ID: report--9cf0c013-bd0d-5789-b783-99624e0f2427
Feed Name: Huntress Blog
Huntress documents a multi-stage ClickFix social-engineering campaign that persuades victims to paste mshta commands (via fake human-verification or Windows Update pages) which run PowerShell to load a reflective .NET loader; that loader AES-decrypts an embedded PNG and uses a custom steganography routine to extract Donut-packed shellcode that injects LummaC2 or Rhadamanthys infostealers into processes. The report includes deobfuscated code excerpts, recovered AES keys, IOCs (domains, IPs, stage URLs), pivot methods, and recommended mitigations such as disabling the Run dialog and user training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
