logo

New ClickFix wave infects users with hidden malware in images and fake Windows updates

ID: 3c7626a0-0aa8-53f3-9c76-beb51581b145

STIX ID: report--3c7626a0-0aa8-53f3-9c76-beb51581b145

Feed Name: Malwarebytes Blog

Threat Score
75/100

Date Published: 2025-11-25

Date Updated: 2026-04-28

...
...

This report details the ClickFix campaign that now impersonates the Windows Update screen to socially engineer victims into running an mshta command that retrieves a multi-stage payload: JScript → obfuscated PowerShell → .NET loader → steganography-extracted shellcode which is injected into trusted processes and delivers info-stealers (Rhadamanthys, LummaC2). It explains the steganographic technique (payload hidden in PNG red-channel pixel data), enumerates the infection stages and common evasion methods (hex-encoded URLs, obfuscation, in-memory execution), and offers user-focused mitigations such as avoiding copy-paste of commands, using real-time anti-malware, and browser protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.