logo

Investigating a New Click-Fix Variant

ID: a0baee8c-d604-51dc-abd8-b51d69a7cdee

STIX ID: report--a0baee8c-d604-51dc-abd8-b51d69a7cdee

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2026-03-13

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

**Executive summary:** Atos researchers describe a ClickFix campaign that coerces users via a phishing page to run a Win+R command which maps a WebDAV share and executes an update.cmd to download a trojanized WorkFlowy Electron app; the malicious app replaces resources/app.asar with an obfuscated main.js that beacons to a C2, fingerprints victims, and can download/execute additional payloads, evading Microsoft Defender and requiring RunMRU-focused threat hunting; IOCs and a detection query are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.