logo

‘Fix It’ social-engineering scheme impersonates several brands

ID: 7b584fe8-4a5a-50e2-b68f-6e4522715f2e

STIX ID: report--7b584fe8-4a5a-50e2-b68f-6e4522715f2e

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2024-12-19

Date Updated: 2026-04-28

...
...

Malicious ads and lookalike software/download pages are luring victims to a fake Cloudflare verification that copies a PowerShell command to the clipboard; victims are instructed to open Run and paste/execute the command, which downloads a payload from topsportracing.com and sends system fingerprinting data to a Cloudflare-tunnelled C2 (peter-secrets-diana-yukon.trycloudflare.com). The campaign targets multiple brands (Notepad++, Teams, FileZilla, etc.), includes several malicious domains, IPs and download URLs as IoCs, and likely delivers an infostealer or RAT.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.