New Execution Technique in ClearFake Campaign
ID: 870e7de3-d716-521e-a5bb-261441a3a71c
STIX ID: report--870e7de3-d716-521e-a5bb-261441a3a71c
Feed Name: ReliaQuest Blog
ReliaQuest observed a ClearFake JavaScript framework campaign that tricks victims into manually pasting obfuscated PowerShell into a shell to fetch and execute additional stages, performing sandbox-evasion (CPU temperature check), DLL sideloading of a malicious MediaInfo DLL, and ultimately installing LummaC2 infostealer; the report includes case studies, IoCs (hashes, domains, IPs), and mitigation recommendations such as restricting PowerShell, applying WDAC/AMSI, network filtering, and user awareness.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
