logo

ClickFix Removes Your Background but Leaves the Malware

ID: bb2fe805-9ec8-5c7e-bb08-37dd57f525f7

STIX ID: report--bb2fe805-9ec8-5c7e-bb08-37dd57f525f7

Feed Name: Huntress Blog

Threat Score
78/100

Date Published: 2026-04-30

Date Updated: 2026-05-01

...
...

This report dissects a multi-stage malicious campaign that lures victims to a fake background-removal site which copies a paste-and-run command that uses the legacy finger protocol to fetch a first-stage payload; that chain ultimately installs CastleLoader to orchestrate encrypted shellcode, a reflective PE loader, NetSupport RAT drops, and a custom .NET stealer (CastleStealer) capable of browser credential, wallet and Telegram session theft; the analysis includes detailed behavioral TTPs, code-level techniques for evasion and persistence, network and file IOCs (domains, URLs, IPs, hashes), and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.