logo

ClickFix Gets Creative: Malware Buried in Images

ID: 9cf0c013-bd0d-5789-b783-99624e0f2427

STIX ID: report--9cf0c013-bd0d-5789-b783-99624e0f2427

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2025-11-24

Date Updated: 2026-04-28

...
...

Huntress documents a multi-stage ClickFix social-engineering campaign that persuades victims to paste mshta commands (via fake human-verification or Windows Update pages) which run PowerShell to load a reflective .NET loader; that loader AES-decrypts an embedded PNG and uses a custom steganography routine to extract Donut-packed shellcode that injects LummaC2 or Rhadamanthys infostealers into processes. The report includes deobfuscated code excerpts, recovered AES keys, IOCs (domains, IPs, stage URLs), pivot methods, and recommended mitigations such as disabling the Run dialog and user training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.