logo

ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures

ID: 7ca5934b-2b0d-5a1f-aa29-35edb5ad11a9

STIX ID: report--7ca5934b-2b0d-5a1f-aa29-35edb5ad11a9

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-06-16

Date Updated: 2026-06-17

Author: [email protected] (The Hacker News)

...
...

Researchers have observed multiple ClickFix-based campaigns delivering three loaders — BabaDeda Loader, Lorem Ipsum Loader, and Potemkin — used to deploy information-stealers, RATs (including EtherRAT, DanaBot, SectopRAT), and to facilitate ransomware operations. The report outlines delivery methods (malicious PowerShell commands, compromised WordPress lures, ZIP archives with DLL side-loading, MSI/HTA), advanced loader features (in-memory reflective loading, staged storage crypter, DGA-driven C2), targeted sectors (education, finance, and others), and post-exploitation activities including persistence, Defender exclusions, tunneling, and lateral movement to domain controllers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.