Search/ClickFix Moves into the Browser to Steal Cryptocurrency
Story

ClickFix Moves into the Browser to Steal Cryptocurrency

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). Over the past months, researchers identified more than 5,400 hacked websites, most of them built on WordPress and PrestaShop. The initial compromise method remains unknown, but each site was injected with a script that gets the next-stage payload from a smart contract on the BSC Testnet endpoint, a technique known as EtherHiding. Researchers at cloud security platform Netskope explain that the BSC Testnet is designed for developers and functions similarly to the mainnet, the production blockchain, but is available free of charge. Threat actors use the EtherHiding technique to store malicious code or…

CVEs
0
Highest CVSS
In KEV
0
Sources
3
Connections
8 relationships
ClickFix Moves into the Browser to Steal Cryptocurrency
A ClickFix campaign has shifted from tricking users into running commands on their computers to persuading them to inject malicious JavaScript into their own browsers, in a scheme aimed at people willing to commit fraud. Cisco Talos said in research published September 8 that the months-long campaign used the Google Visualization API to retrieve obfuscated code from a public Google Sheets document and inject it into sessions on two cryptocurrency trading sites. The operation has survived two disruption attempts. Talos alerted Google and the targeted sites in April, and the campaign returned a week later on a new spreadsheet; as of August 11 the replacement Google documents had been reported again but remained live. ClickFix Moves From the OS to the Browser The campaign began in October 2025 with lures instructing targets to paste JavaScript into Chrome's navigation bar. The operators added the Visualization API in March 2026 and, from mid-April, told victims to install the Tampermonkey browser extension before adding a script. The lures posed as leaked vulnerability reports describing non-existent API flaws at cryptocurrency swap services, promising payouts up to 38% higher. Talos said the appeal was to readers prepared to exploit a flaw they did not understand. Talos found the material on Telegram, the cybercrime forum DarkForums and text-sharing sites, with waves of messages sent at least twice a month. The Visualization API gives free, unauthenticated read-only access to any Google Sheets document published to the web, so the request came from the victim's own browser and resembled ordinary web traffic. The operators hid the payload cells by formatting the text white on white. Talos collected 21 second-stage payloads from the spreadsheet, rotated with fresh XOR keys and randomized variable names but functionally unchanged. Injected Scripts Turn Browser Into Crypto Skimmer The scripts monitored page changes, replaced displayed deposit addresses and altered transaction amounts to suggest a bonus had been applied. They also overrode the browser's fetch API, substituting attacker wallet addresses into deposit responses before the data reached the page. A clipboard function replaced any address the victim copied. On the Tampermonkey version, the code reloaded on every visit to the targeted site. Talos identified 49 Bitcoin addresses across the campaign. Most samples it decoded, covering April to late June, drew on one set of 30, of which 24 received victim funds totaling 0.159 BTC, about $10,000 at early August valuations. The researchers said the real figure was probably higher, and that proceeds were routed through 30 further wallets and then more than 3000 addresses in what looked like a mixing operation. Talos said the campaign posed no specific threat to most organizations but that the techniques did, and advised restricting browser extensions by role and monitoring browser sessions for requests to Google Docs.
infosecurity-magazine.comSep 9, 2026extracted
Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). Over the past months, researchers identified more than 5,400 hacked websites, most of them built on WordPress and PrestaShop. The initial compromise method remains unknown, but each site was injected with a script that gets the next-stage payload from a smart contract on the BSC Testnet endpoint, a technique known as EtherHiding. Researchers at cloud security platform Netskope explain that the BSC Testnet is designed for developers and functions similarly to the mainnet, the production blockchain, but is available free of charge. Threat actors use the EtherHiding technique to store malicious code or configuration data in blockchain smart contracts, providing a resilient infrastructure that is difficult to take down. In the delivery chain observed by Netskope, the script displays a ClickFix lure that shows a fake CAPTCHA and instructs visitors to open the Windows Run dialog and paste a PowerShell command. Doing so downloads and executes the final payload on the machine. Because the attacker stores the payload in a smart contract, they can modify it at any time. The researchers note that later in the campaign, the threat actor replaced the ClickFix payload in the smart contract with a WebRTC data-channel stager. In the newer variant, the payload establishes a covert encrypted channel to the attacker and executes the received code. “The script creates a peer connection and a data channel, then generates the required session description offer just like a normal WebRTC handshake,” Netskope explains. “But instead of sending that offer anywhere and waiting for a real reply, it hand-writes the answer itself and feeds it straight back into the connection. This way, no handshake happens, but a data channel to the cyberattacker still opens.” The stager receives JavaScript code from the hardcoded command-and-control (C2) address, buffers it, and executes it when the channel closes or after ten seconds. Received code is assembled in the browser memory and executed dynamically without being saved to disk by adding it to the head of the DOM Netskope warns that the operation uses more than 300 infected websites every day. Since spring, the number of compromised sites contacting the BSC Testnet RPC endpoints has grown constantly. Telemetry data shows that nearly 400 websites called the endpoint every day in August, with an all-time peak of 536. The security researchers recommend that defenders block the entire pool of BSC testnet RPC endpoints provided here and monitor for non-web UDP traffic associated with WebRTC. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comSep 5, 2026extracted
Related Stories
6
Researchers uncover ClickFix-themed phishing kit
Cybersecurity researchers are calling attention to a nefarious campaign targeting WordPress sites to make malicious JavaScript injections that are designed to redirect users to sketchy sites. "Site visitors get injected content that was drive-by malware like fake Cloudflare verification," Sucuri researcher Puja Srivastava said in an analysis published last week. The website security company said it began an investigation after one of its customer's WordPress sites served suspicious third-party JavaScript to site visitors, ultimately finding that the attackers introduced malicious modifications to a theme-related file ("functions.php"). The code inserted into "functions.php" incorporates references to Google Ads, likely in an attempt to evade detection. But, in reality, it functions as a remote loader by sending an HTTP POST request to the domain "brazilc[.]com," which, in turn, responds with a dynamic payload that includes two components - A JavaScript file hosted on a remote server ("porsasystem[.]com"), which, as of writing, has been referenced on 17 websites and contains code to perform site redirects A piece of JavaScript code that creates a hidden, 1x1 pixel iframe, within which it injects code that mimics legitimate Cloudflare assets like "cdn-cgi/challenge-platform/scripts/jsd/main.js" – an API that's a core part of its bot detection and challenge platform It's worth noting that the domain "porsasystem[.]com" has been flagged as part of a traffic distribution system (TDS) called Kongtuke (aka 404 TDS, Chaya_002, LandUpdate808, and TAG-124). According to information shared by an account named "monitorsg" on Mastodon on September 19, 2025, the infection chain starts with users visiting a compromised site, resulting in the execution of "porsasystem[.]com/6m9x.js," which then leads to "porsasystem[.]com/js.php" to eventually take the victims to ClickFix-style pages for malware distribution. The findings illustrate the need for securing WordPress sites and ensuring that plugins, themes, and website software are kept up-to-date, enforcing strong passwords, scanning the sites for anomalies and unexpected administrator accounts created for maintaining persistent access even after the malware is detected and removed. Create ClickFix Pages Using IUAM ClickFix Generator The disclosure comes as Palo Alto Networks Unit 42 detailed a phishing kit named IUAM ClickFix Generator that allows attackers to infect users with malware by leveraging the ClickFix social engineering technique and come up with customizable landing pages by mimicking browser verification challenges often used to block automated traffic. "This tool allows threat actors to create highly customizable phishing pages that mimic the challenge-response behavior of a browser verification page commonly deployed by Content Delivery Networks (CDNs) and cloud security providers to defend against automated threats," security researcher Amer Elsad said. "The spoofed interface is designed to appear legitimate to victims, increasing the effectiveness of the lure." The bespoke phishing pages also come with capabilities to manipulate the clipboard, a crucial step in the ClickFix attack, as well as detect the operating system used in order to tailor the infection sequence and serve compatible malware. In at least two different cases, threat actors have been detected using pages generated using the kit to deploy information stealers such as DeerStealer and Odyssey Stealer, the latter of which is designed to target Apple macOS systems. The emergence of the IUAM ClickFix Generator adds to a prior alert from Microsoft warning of a rise in commercial ClickFix builders on underground forums since late 2024. Another notable example of a phishing kit that has integrated the offering is Impact Solutions. "The kits offer creation of landing pages with a variety of available lures, including Cloudflare," Microsoft noted back in August 2025. "They also offer construction of malicious commands that users will paste into the Windows Run dialog. These kits claim to guarantee antivirus and web protection bypass (some even promise that they can bypass Microsoft Defender SmartScreen), as well as payload persistence." It goes without saying that these tools further lower the barrier to entry for cybercriminals, enabling them to mount sophisticated, multi-platform attacks at scale without much effort or technical expertise. ClickFix Becomes Stealthy via Cache Smuggling The findings also follow the discovery of a new campaign that has innovated on the ClickFix attack formula by employing a sneaky technique referred to as cache smuggling to fly under the radar as opposed to explicitly downloading any malicious files on the target host. "This campaign differs from previous ClickFix variants in that the malicious script does not download any files or communicate with the internet," Expel Principal Threat Researcher Marcus Hutchins said. "This is achieved by using the browser's cache to pre-emptively store arbitrary data onto the user's machine." Expel said it was unable to determine the final payload received as part of the attack. It's also currently not known how users are redirected to the phishing page, and if it involves techniques like malvertising or search engine optimization (SEO) poisoning. In the attack documented by the cybersecurity company, the ClickFix-themed page masquerades as a Fortinet VPN Compliance Checker, using FileFix tactics to deceive users into launching the Windows File Explorer and pasting a malicious command into the address bar to trigger the execution of the payload. The invisible command is designed to run a PowerShell script via conhost.exe. What makes the script stand apart is that it does not download any additional malware or communicate with an attacker-controlled server. Instead, it executes an obfuscated payload that passes off as a JPEG image and is already cached by the browser when the user lands on the phishing page. "The file extracted from the cache is used to set up a scheduled task, which is set to run after each reboot," Hutchins told The Hacker News. "When the task runs, it connects to a command-and-control server waiting for follow-up commands." "Neither the web page nor the PowerShell script explicitly downloads any files," Hutchins explained. "By simply letting the browser cache the fake 'image,' the malware is able to get an entire ZIP file onto the local system without the PowerShell command needing to make any web requests." "The implications of this technique are concerning, as cache smuggling may offer a way to evade protections that would otherwise catch malicious files as they are downloaded and executed. An innocuous-looking 'image/jpeg' file is downloaded, only to have its contents extracted and then executed via a PowerShell command hidden in a ClickFix phishing lure." (The story was updated after publication to include additional insights from Expel.)
3 shared
Oct 8, 2025
ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain
Microsoft has published details about a Windows malware campaign it calls TerminalFix. The social engineering used to infect people is very similar to what we’ve seen in ClickFix campaigns. A website visitor is presented with a fake Cloudflare CAPTCHA which, when clicked, secretly copies a malicious command to their clipboard. Then they receive instructions on what they need to do to “prove they are human,” when in reality they are being instructed to execute the malicious command. After gaining a foothold, the malware downloads what appear to be ordinary PNG images from attacker-controlled sites, but the images also contain concealed payload data. A PowerShell script reads the images’ pixel data: The first eight bytes specify the embedded file’s length, while the remaining data is reconstructed into an executable and two DLL fragments, which are joined on the victim’s disk. The use of steganography is notable, but does not set TerminalFix apart from other ClickFix campaigns that have used the same method. What does make TerminalFix different is its payload. One way or another , ClickFix victims usually end up with information-stealing malware of some sort. TerminalFix instead chains together several mature evasion techniques, including DLL sideloading, steganographic delivery, folder hiding, realistic browser User-Agent rotation, and encrypted WebSocket traffic, rather than relying on one obfuscated PowerShell downloader. Its end goal is also different. The campaign delivers a payload chain that performs domain-aware reconnaissance before installing a custom, multiplexed reverse TCP tunnel. This hidden connection can give attackers access to the victim’s network. The infected computer first calls out to the attackers using encrypted web-like traffic over port 443, allowing the “reverse” connection to pass more easily through a company firewall. In this way, the compromised system creates a secret remote-access doorway from inside the network. “Multiplexed” means the attackers can send several separate connections, for example to a file server, database, or another workstation, through that single encrypted tunnel at the same time. This allows them to use the victim’s computer as a stepping stone into the rest of the network. How to stay safe First, remember that a real CAPTCHA may ask you to click boxes or select images, but it will not ask you to open Run, Terminal, Command Prompt, or PowerShell and paste a command. Slow down.  Don’t rush to follow instructions on a webpage or prompt, especially if it asks you to run commands on your device or copy-paste code. Attackers rely on urgency to discourage careful thought, so be cautious of pages urging immediate action. Sophisticated ClickFix pages may add countdowns, user counters, or other pressure tactics to make you act quickly. Avoid running commands or scripts from untrusted sources.  Never run code or commands copied from websites, emails, or messages unless you trust the source and understand exactly what the command will do. Verify instructions independently.  If a website tells you to execute a command or perform a technical action, check through official documentation or contact support before proceeding. Limit the use of copy and paste for commands.  Manually typing commands instead of copy-pasting can reduce the risk of unknowingly running malicious payloads hidden in copied text. Secure your devices.  Use an up-to-date, real-time  anti-malware solution  with a web protection component. Learn to recognize evolving attack techniques.  Knowing that attackers continually change their methods can help you recognize suspicious instructions. Keep reading our blog! Pro tip:  Did you know that the free  Malwarebytes Browser Guard  extension warns you when a website tries to copy something to your clipboard? Some browsers also restrict or warn about certain uses of the clipboard. Since macOS Tahoe 26.4 , Terminal can warn users when they paste text copied from a browser or messaging app. This protection operates at the app and operating-system level rather than inside the browser. Stop threats before they can do any harm. Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
3 shared
Sep 5, 2026
ClickFix Attacks Against macOS Users Evolving
ClickFix attacks have evolved to feature videos that guide victims through the self-infection process, a timer to pressure targets into taking risky actions, and automatic detection of the operating system to provide the correct commands. In a typical ClickFix attack, the threat actor relies on social-engineering to trick users into pasting and executing code or commands from a malicious page. The lures used may vary from identity verification to software problem solutions. The goal is to make the target execute malware that fetches and launches a payload, usually an information stealer. Most of the times, these attacks provided text instructions on a web page but newer versions rely on an embedded video to make the attack less suspicious. Push Security researchers have spotted this change in recent ClickFix campaigns, where a fake Cloudflare CAPTCHA verification challenge detected the victim’s OS and loaded a video tutorial on how to paste and run the malicious commands. Through a JavaScript, the threat actor can hide the commands and copy them automatically into the user's clipboard, thus reducing the chances of human error. On the same window, the challenge included a one-minute countdown timer that presses the victim into taking quick action and leaving little time to verify the authenticity or safety of the verification process. Adding to the deception is a “users verified in the last hour” counter, making the window appear as part of a legitimate Cloudflare bot check tool. Although we have seen ClickFix attacks against all major operating systems before, including macOS and Linux, the automatic detection and adjustment of the instructions is a new development. Push Security reports that these more advanced ClickFix webpages are promoted primarily through malvertizing on Google Search. The threat actors either exploit known flaws on outdated WordPress plugins to compromise legitimate sites and inject their malicious JavaScript on pages, or “vibe-code” sites and use SEO poisoning tactics to rank them higher up in the search results. Regarding the payloads delivered in these attacks, Push researchers noticed that they depended on the operating system, but included the MSHTA executable in Windows, PowerShell scripts, and various other living-off-the-land binaries. The researchers speculate that future ClickFix attacks could run entirely in the browser, evading EDR protections. As ClickFix evolves and takes more convincing and deceptive forms, users should remember that executing code on the terminal can never be a part of any online-based verification process, and no copied commands should ever be executed unless the user fully understands what they do. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
3 shared
Nov 12, 2025
US Tops Hit List as 396 SharePoint Systems Compromised Globally
Check Point Research (CPR) conducted a focused analysis of Storm-2603, a threat actor associated with recent ToolShell exploitations, together with other Chinese APT groups. Storm-2603 utilizes a custom malware Command and Control (C2) framework dubbed internally by the attacker as “ak47c2”. This framework includes at least two different types of clients: HTTP-based (dubbed by us “ak47http”) and DNS-based (dubbed by us “ak47dns”). Based on VirusTotal data, Storm-2603 likely targeted some organizations in Latin America throughout the first half of 2025, in parallel to attacking organizations in APAC. Some of the actor’s TTPs align with many other ransomware groups, and involve open-source tools such as PsExec and masscan. In addition, the threat actors use a custom tool that leverages the BYOVD (Bring Your Own Vulnerable Driver) technique to tamper with endpoint protections. Storm-2603 attacks involved multiple ransomware families, sometimes bundled together. Those are commonly deployed by abusing DLL hijacking. Check Point Research (CPR) has been closely monitoring the ongoing exploitation of a group of Microsoft SharePoint Server vulnerabilities collectively referred to as “ToolShell.” These active attacks leverage four vulnerabilities—CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771—and are attributed to multiple China affiliated threat actors. Among the threat groups identified by Microsoft, two are known APTs: Linen Typhoon (aka APT27) and Violet Typhoon (aka APT31). Another group is a newly observed, previously undocumented cluster called Storm-2603. While Microsoft linked this cluster’s activity to potential ransomware deployment, it was unable to assess the group’s objectives. As part of our ongoing investigation into ToolShell and its associated risks, we launched a targeted effort to better understand and characterize the threat posed by Storm-2603. Throughout our analysis, we uncovered several files likely tied to Storm-2603 intrusions, offering new insights that correspond to Microsoft’s description of the group. In this publication, we provide an in-depth examination of Storm-2603’s tactics, techniques, and procedures (TTPs), along with a technical breakdown of the ak47c2, a custom malware framework used in their attacks and their different ransomware payloads. Storm-2603 was first mentioned by Microsoft during investigations into a set of attacks on Microsoft SharePoint servers, known as the “ToolShell” campaign. While some activity was tied to known Chinese affiliated groups like Linen Typhoon (APT27) and Violet Typhoon (APT31), Storm-2603 appeared as a new, previously unreported actor. Microsoft linked the group to Lockbit and Warlock ransomware use. Figure 1 – Events associated with Storm-2603. Microsoft’s report provided only limited information about Storm-2603, including some of the TTPs associated with it, most of them quite generic. In addition, some of the reported indicators of compromise (IOCs) helped us uncover additional artifacts associated with previous Storm-2603 intrusions. One domain in particular, update.updatemicfosoft[.]com, linked to Storm-2603’s SharePoint exploitation, turned out to have been used in earlier campaigns dating back to March 2025. In those operations, it served as a C2 server for both DNS tunneling malware and an HTTP backdoor and was part of infrastructure used to deliver LockBit Black and Warlock/x2anylock ransomware. Our search for cases where the IOCs reported by Microsoft, revealed two incidents in which LockBit Black and WarLock ransomware variants were deployed together, in addition to multiple other tools, mostly open-source. In April 2025, a RAR archive named Evidencia.rar was uploaded to VirusTotal. The archive contains several artifacts likely extracted from compromised machines in a Storm-2603 case in a LATAM country. The artifacts in the archive provide a look at some of the open-source tools used by the actors in the intrusions which correlates with previous knowledge of the group: WinPcap – Captures and filters network traffic on Windows. PsExec – Executes commands on remote Windows systems. SharpHostInfo – Collects host and domain info on Windows environments. nxc – Exploits common vulnerabilities in network services. In addition to the open-source tools, the archive also contains the custom backdoor used by the group, as well as its unique ransomware payloads. dnsclient.exe – A custom backdoor utilized by Storm-2603 that communicates over DNS tunneling with update.updatemicfosoft[.]com, a domain associated with the group. See the next section for our analysis of the backdoor. 7z.exe & 7z.dll – Legitimate 7z executable side-loading malicious 7z.dll delivering X2anylock (aka Warlock), a ransomware used by Storm-2603. bbb.msi – An installer which uses clink_x86.exe to side-load clink_dll_x86.dll, leading to the execution of LockBit Black ransomware. Another MSI file uploaded to VirusTotal in April used a similar deployment method, starting with the MSI installer to launch multiple ransomware strains simultaneously: Figure 2 – MSI Multi-Ransomware Deployment. The MSI relies on the following files: MpCmdRun.exe & Mpclient.dll – Warlock Ransomware, deployed via DLL-hijacking. clink_x86.exe & clink_dll_x86.dll – LockBit Black ransomware, deployed via DLL-hijacking. z.exe & z.dll – x2anylock ransomware, deployed via DLL-hijacking. VMToolsEng.exe – Custom Antivirus Terminator. ServiceMouse.sys – Vulnerable driver used by VMToolsEng.exe for killing Antivirus processes. log.exe – A list of Antivirus processes to kill. msi.bat – Executes VMToolsEng.exe. 1.bat – Executes all the needed executables and the MSI. We attributed two custom backdoors to Storm-2306, both of which appear to be part of the framework named AK47 C2 based on the shared PDB path: C:\Users\Administrator\Desktop\work\tools\ak47c2\. When executed, the program immediately hides its console window, determines the host computer name (defaulting to unknown.local if that fails), and builds a DNS‑based command‑and‑control payload. It chooses a random five-character session ID, such as H4T14, and prefixes it with 1 for task requests or 2 for result uploads (e.g., 1H4T14 or 2H4T14). Each element, such as the task/result tag, a size flag (a for “all” when the entire message fits into one request), and the computer name, is XOR‑encoded with the ASCII key “VHBD@H”, converted to hexadecimal, and concatenated with dots before being prepended to the C2 domain update.micfosoft[.]com. This what the overall query looks like: DNS TXT and MG (a mail group member record type) record lookups (DnsQuery_A) are used to transmit and retrieve data. If the C2 server is unreachable, the client simply receives error 9003 (DNS_ERROR_RCODE_NAME_ERROR). Otherwise, the response text is decoded from hex, XOR‑decrypted, and parsed for the delimiter “:::”, which separates metadata from the actual command string. Commands run under cmd.exe /c 2>&1; a built‑in directive sleep n pauses execution for n seconds. For outputs larger than 0xFF bytes, the backdoor fragments data into 63‑byte sub‑segments. Each DNS query then follows: HttpClient backdoor has the pdb path C:\Users\Administrator\Desktop\work\tools\ak47c2\httpclient-cpp\x64\Release\httpclient-cpp.pdb and uses plain HTTP instead of DNS for the C2. It is built as a 64‑bit console program that also immediately hides its window on launch. On start‑up, the malware gathers the host computer name (similar to the DNS version, it defaults to unknown.local), then builds a JSON object with the fields cmd, cmd_id, fqdn, result, and type. For a task request, the object looks like this: {"cmd":"","cmd_id":"","fqdn":" ","result":"","type":"task"} After the host executes a command, the result is sent back with type:”result”. Before transmission, the entire JSON blob is XOR‑encrypted with the ASCII key “VHBD@H”, converted to hexadecimal, and placed in the body of an HTTP POST to “/” with generic headers (Content‑Type: text/plain, Accept: */*). The C2 replies with a similarly encoded JSON where the cmd field contains the next command. The implant executes it via cmd.exe /c 2>&1 and returns the output. We identified that during these attacks, several types of ransomware were deployed simultaneously. One is regular LockBit Black, and the second uses the.x2anylock extension. This extension was later used by the Warlock ransomware operator, mentioned in Microsoft’s report on the SharePoint exploitation. The Warlock ransom note is usually saved as How to decrypt my data.txt and looks like this: Figure 3 – Warlock Group ransom note. The ransom notes for all ransomware strains deployed by Storm-2603 are named How to decrypt my data.log (x2anylock) or .README.txt (LockBit Black) and have the same short content: Your decrypt ID: [redacted] Tox ID Support: 3DCE[redacted] Email Support: [redacted]@proton.me,[redacted]@proton.me,[redacted]@proton.me You can contact us in email or qtox. This ransom note’s name How to decrypt my data.log appeared in a recent LinkedIn post by Huntress, describing the case where multiple ransomware families were deployed together against the same target. While not a new tactic, this approach is rarely observed among established ransomware groups. An important part of the infection package described earlier is called Antivirus Terminator. It is a custom command line tool abusing a third-party signed legitimate driver to kill processes. From what we can see, it’s been in the wild since at least late 2024. The tool requires administrative privileges on the infected machine. The screenshot below shows how the listing is displayed in the console when the tool is run without parameters: Figure 4 – Antivirus Terminator supported arguments when run without parameters. The tool first creates a service called ServiceMouse, where the path to the service binary file is ServiceMouse.sys from the package. Next, the tool communicates with the installed service via IO control code 0x99000050, which is responsible for killing processes. The tool also has more capabilities, like deleting files and uninstalling drivers, and these use different IO control codes (0x990000D0 and 0x990001D0). Figure 6 – Antivirus Terminator kills process using third-party driver. The supplied third-party driver is a legitimate and signed component of Antiy System In-Depth Analysis Toolkit, originally named AToolsKrnl64.sys. The toolkit was developed by Antiy Labs, a Chinese security vendor, and features a graphical user interface that allows users, among others, to interact with and manipulate processes. The ability to kill processes is the most important feature which is abused by threat actors in this particular case. Figure 7 – Antiy System In-Depth Analysis Tookit GUI. The following piece of code in the driver handles the IO control code 0x99000050 mentioned above: Figure 8 – IO control code processing in the Antiy driver. The second function is the piece of code responsible for killing a process with a given PID. In this report we analyze Storm-2603, a relatively new threat actor first mentioned by Microsoft during investigations into the “ToolShell” campaign targeting SharePoint servers. While some of the exploitation activity was tied to known Chinese APT groups, Storm-2603 stood out as a previously undocumented group linked to ransomware deployment. By examining infrastructure indicators shared in public reporting, we were able to connect this actor to earlier campaigns involving LockBit Black and Warlock/X2anylock ransomware, dating back to at least March 2025. These earlier attacks used similar infrastructure and tools, including DNS tunneling and HTTP-based backdoors. Interestingly, multiple ransomware variants were deployed in the same attack. This behavior, along with the overlap in techniques, helps us better understand how Storm-2603 operates “The Turkish Rat” Evolved Adwind in a Massive Ongoing Phishing Campaign Check Point Research Publications August 11, 2017 “The Next WannaCry” Vulnerability is Here Check Point Research Publications March 12, 2026 “Handala Hack” – Unveiling Group’s Modus Operandi SUBSCRIBE TO CYBER INTELLIGENCE REPORTS We value your privacy! BFSI uses cookies on this site. We use cookies to enable faster and easier experience for you. By continuing to visit this website you agree to our use of cookies.
2 shared
Aug 1, 2025
From ClickFix to MetaStealer: Dissecting Evolving Threat Actor Techniques
By John Hammond, Alden Schmidt, Lindsey Welch During the past fifteen business days, Huntress analysts have observed increased threat activity involving several notable techniques. One case involved a malicious AnyDesk installer, which initially mimicked a standard ClickFix attack through a fake Cloudflare verification page but then utilized Windows File Explorer and an MSI package masked as a PDF to deploy MetaStealer malware. Additionally, two incidents involving the Cephalus ransomware variant were detected. This ransomware distinguishes itself by employing DLL sideloading through a legitimate SentinelOne executable, SentinelBrowserNativeHost.exe, to launch the payload. These recent findings highlight the ongoing evolution in threat actor tradecraft, combining established social engineering methods with more technically advanced infection chains and evasive deployment strategies. ClickFix attacks have been ticking up for over a year now, as attackers find success in tricking users into executing malicious code on their computers using CAPTCHA-based lures. We’ve seen quite a bit of these types of attacks on our end, but we’ve also seen threat actors adopting ClickFix-esque techniques in attacks that don’t follow the exact ClickFix playbook. Recently, our very own John Hammond received an email from someone who had come across a fake AnyDesk installer while searching for the AnyDesk remote tool. While early indicators of the attack look like it would turn into another ClickFix scam, a little bit of digging shows a unique infection chain that involves a fake Cloudflare Turnstile lure, the Windows search protocol, and an MSI package disguised as a PDF that cleverly grabs the victim’s hostname. The attack ultimately aims to drop MetaStealer, a commodity infostealer that’s been around since 2022 and is known for harvesting credentials and stealing files. ClickFix, FileFix, and other ‘fix’ variants First, a quick primer on the widely used ClickFix technique. The premise of ClickFix is that threat actors convince users to “fix” a purported issue, usually with a CAPTCHA on a webpage that they arrive on via a phishing message, or otherwise. The “solution” is copying and pasting a command fed to victims via an attacker-controlled prompt, which quietly kicks off the attack chain. While the classic ClickFix attack tricks users to paste and run commands in their Windows Run dialog box or via PowerShell, other variants of the attack have also sprung up that take a different approach. A few months ago, attackers turned to a similar technique, dubbed FileFix, which involves Windows File Explorer instead of the Run dialog box. We’ve seen a number of incidents that stem from ClickFix attacks. In the August 26 incident shown in Figure 1 below, for instance, we responded to an attack where a user executed a malicious command given to them via a fake Cloudflare Turnstile, which is Cloudflare’s verification tool meant to replace CAPTCHAs for weeding out bots. This then downloaded and installed an infostealer. Closer investigation revealed that the victim had visited the landing page teams-one[.]com. This page showed a Cloudflare Turnstile and marked the beginning stage of the ClickFix attack. Though there are similarities that we’ll outline below, the run-of-the-mill ClickFix incident demonstrated above differs significantly from the MetaStealer attack that we recently came across. Hacker tradecraft’s evolving daily, so let’s break it down on Tradecraft Tuesday! Join us monthly for an in-depth look at attacker tradecraft—no sales or product talk involved. Sign up for the series today or catch up on previous episodes. No tricks, just tradecraft. Register for Tradecraft Tuesday A ClickFix-turned-not-fix attack: what we saw The initial link for the fake AnyDesk installer redirects users to https[://]anydeesk[.]ink/download/anydesk[.]html, which displays a Cloudflare Turnstile - and a very questionable UI. The page purports to support “Secure Access Verification”, prompting the user to click a single button on the Cloudflare Turnstile to “verify you are human.” A quick look at the underlying HTML for the webpage (using View Source) is shrouded by obfuscated JavaScript, but that can be easily unraveled with JavaScript deobfuscation tools available in the browser tools console. This reveals the actual source code - and reveals the window.location.href value to be https[://]verification[.]anydeesk[.]ink/reCAPTCHA-v2[.]php. Up to this point, this has all the tell-tale signs of a ClickFix campaign: it involves a classic human verification social engineering piece, and sets the end user up to click on a box. However, when the victim clicks the box, the prompts in this attack lead to Windows File Explorer, Windows’ file management tool, as opposed to the Windows Run dialog box as we have seen with ClickFix. This is more indicative of a FileFix attack—but this attack still isn’t strictly FileFix, where victims are prodded to launch the address bar in Windows File Explorer (using a Ctrl+L and Ctrl+V combination to paste a PowerShell command that was automatically copied to their clipboard). Instead, in this attack, the PHP above redirects users to the Windows protocol handler (search-ms URI), a legitimate feature enabling applications to kick off specific search queries in Windows File Explorer. The specific Windows File Explorer “Search” redirect location can be seen in Figure 4 below, which displays the name for a custom search query as part of the search-ms URI protocol. As seen in Figure 5 below, Windows File Explorer then directs the victim to an attacker-controlled SMB share, essentially a remote file share allowing clients to access files on a remote server over a network. Here, victims are presented with a Windows shortcut LNK file – however, this LNK file is disguised as a PDF file called Readme Anydesk.pdf. Fake PDF lure: snagging victim hostnames As you can see below, the LNK file’s payload is: Once clicked, this file’s payload kicks off a few processes. Here, cmd.exe starts the automatic download of a legitimate AnyDesk installer on Microsoft Edge, possibly as a way to avoid suspicion for the victim. Meanwhile, it also begins a download for another purported “PDF,” which is downloaded from chat1[.]store and dropped into the temporary directory. Notably, this fake PDF is configured to grab the %COMPUTERNAME% environment variable as a subdomain. Subdomains don’t need to know the user’s hostname ahead of time, so this is a clever way for the attacker to nab that information from the victim. The fake PDF is then installed by msiexec (revealing that it’s actually an MSI package) and the cmd.exe process is then killed. Upon closer inspection of chat1[.]store (reached through a curl user agent), we can see everything from the MSI package, including files that would have been triggered as part of the attack chain. The two important files in the MSI package are a DLL (CustomActionDLL) and a CAB archive (Binary.bz.WrappedSetupProgram) which contains several other files. The CAB file contains two additional malicious files: 1.js which is responsible for cleaning up the infection chain, and ls26.exe which is the MetaStealer dropper. The MetaStealer file (ls26.exe) is a very large binary and is protected with Private EXE Protector. Upon further inspection, the executable reveals the same types of behavior that we’ve seen in known samples of MetaStealer, such as stealing from crypto wallets. ClickFix variants and lessons learned ClickFix, FileFix, and even this alternate-ClickFix attack we recently found show the power of blending social engineering with mundane processes, like CAPTCHAs or other verification tools. Additionally, these types of attacks that require some level of manual interaction from the victim, as they work to “fix” the purported broken process themselves, work in part because they can potentially circumvent security solutions. The guidance for organizations in regards to ClickFix has previously centered around taking measures like disallowing users to use the Windows Run dialog box if it’s not needed for everyday tasks. While this can be effective against traditional ClickFix attacks, the variants like the one above show that threat actors are continuing to move the needle in their infection chains, throwing a wrench into detection and prevention. Organizations should take additional measures, including educating users about the lures linked to ClickFix-like attacks. Users should be trained on spotting CAPTCHAs that prompt them to copy and paste into the Run dialog box, or redirect to Windows File Explorer. Maintain Situational Awareness—Register for Tradecraft Tuesday Tradecraft Tuesday provides cybersecurity professionals with an in-depth analysis of the latest threat actors, attack vectors, and mitigation strategies. Each weekly session features technical walkthroughs of recent incidents, comprehensive breakdowns of malware trends, and up-to-date indicators of compromise (IOCs). Participants gain: Detailed briefings on emerging threat campaigns and ransomware variants Evidence-driven defense methodologies and remediation techniques Direct interaction with Huntress analysts for incident response insights Access to actionable threat intelligence and detection guidance Advance your defensive posture with real-time intelligence and technical education specifically designed for those responsible for safeguarding their organization’s environment. IOCs Sponsored and written by Huntress.
2 shared
Sep 23, 2025
The Heat Wasn't Just Outside: Cyber Attacks Spiked in Summer 2025
Check Point Research (CPR) conducted a focused analysis of Storm-2603, a threat actor associated with recent ToolShell exploitations, together with other Chinese APT groups. Storm-2603 utilizes a custom malware Command and Control (C2) framework dubbed internally by the attacker as “ak47c2”. This framework includes at least two different types of clients: HTTP-based (dubbed by us “ak47http”) and DNS-based (dubbed by us “ak47dns”). Based on VirusTotal data, Storm-2603 likely targeted some organizations in Latin America throughout the first half of 2025, in parallel to attacking organizations in APAC. Some of the actor’s TTPs align with many other ransomware groups, and involve open-source tools such as PsExec and masscan. In addition, the threat actors use a custom tool that leverages the BYOVD (Bring Your Own Vulnerable Driver) technique to tamper with endpoint protections. Storm-2603 attacks involved multiple ransomware families, sometimes bundled together. Those are commonly deployed by abusing DLL hijacking. Check Point Research (CPR) has been closely monitoring the ongoing exploitation of a group of Microsoft SharePoint Server vulnerabilities collectively referred to as “ToolShell.” These active attacks leverage four vulnerabilities—CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771—and are attributed to multiple China affiliated threat actors. Among the threat groups identified by Microsoft, two are known APTs: Linen Typhoon (aka APT27) and Violet Typhoon (aka APT31). Another group is a newly observed, previously undocumented cluster called Storm-2603. While Microsoft linked this cluster’s activity to potential ransomware deployment, it was unable to assess the group’s objectives. As part of our ongoing investigation into ToolShell and its associated risks, we launched a targeted effort to better understand and characterize the threat posed by Storm-2603. Throughout our analysis, we uncovered several files likely tied to Storm-2603 intrusions, offering new insights that correspond to Microsoft’s description of the group. In this publication, we provide an in-depth examination of Storm-2603’s tactics, techniques, and procedures (TTPs), along with a technical breakdown of the ak47c2, a custom malware framework used in their attacks and their different ransomware payloads. Storm-2603 was first mentioned by Microsoft during investigations into a set of attacks on Microsoft SharePoint servers, known as the “ToolShell” campaign. While some activity was tied to known Chinese affiliated groups like Linen Typhoon (APT27) and Violet Typhoon (APT31), Storm-2603 appeared as a new, previously unreported actor. Microsoft linked the group to Lockbit and Warlock ransomware use. Figure 1 – Events associated with Storm-2603. Microsoft’s report provided only limited information about Storm-2603, including some of the TTPs associated with it, most of them quite generic. In addition, some of the reported indicators of compromise (IOCs) helped us uncover additional artifacts associated with previous Storm-2603 intrusions. One domain in particular, update.updatemicfosoft[.]com, linked to Storm-2603’s SharePoint exploitation, turned out to have been used in earlier campaigns dating back to March 2025. In those operations, it served as a C2 server for both DNS tunneling malware and an HTTP backdoor and was part of infrastructure used to deliver LockBit Black and Warlock/x2anylock ransomware. Our search for cases where the IOCs reported by Microsoft, revealed two incidents in which LockBit Black and WarLock ransomware variants were deployed together, in addition to multiple other tools, mostly open-source. In April 2025, a RAR archive named Evidencia.rar was uploaded to VirusTotal. The archive contains several artifacts likely extracted from compromised machines in a Storm-2603 case in a LATAM country. The artifacts in the archive provide a look at some of the open-source tools used by the actors in the intrusions which correlates with previous knowledge of the group: WinPcap – Captures and filters network traffic on Windows. PsExec – Executes commands on remote Windows systems. SharpHostInfo – Collects host and domain info on Windows environments. nxc – Exploits common vulnerabilities in network services. In addition to the open-source tools, the archive also contains the custom backdoor used by the group, as well as its unique ransomware payloads. dnsclient.exe – A custom backdoor utilized by Storm-2603 that communicates over DNS tunneling with update.updatemicfosoft[.]com, a domain associated with the group. See the next section for our analysis of the backdoor. 7z.exe & 7z.dll – Legitimate 7z executable side-loading malicious 7z.dll delivering X2anylock (aka Warlock), a ransomware used by Storm-2603. bbb.msi – An installer which uses clink_x86.exe to side-load clink_dll_x86.dll, leading to the execution of LockBit Black ransomware. Another MSI file uploaded to VirusTotal in April used a similar deployment method, starting with the MSI installer to launch multiple ransomware strains simultaneously: Figure 2 – MSI Multi-Ransomware Deployment. The MSI relies on the following files: MpCmdRun.exe & Mpclient.dll – Warlock Ransomware, deployed via DLL-hijacking. clink_x86.exe & clink_dll_x86.dll – LockBit Black ransomware, deployed via DLL-hijacking. z.exe & z.dll – x2anylock ransomware, deployed via DLL-hijacking. VMToolsEng.exe – Custom Antivirus Terminator. ServiceMouse.sys – Vulnerable driver used by VMToolsEng.exe for killing Antivirus processes. log.exe – A list of Antivirus processes to kill. msi.bat – Executes VMToolsEng.exe. 1.bat – Executes all the needed executables and the MSI. We attributed two custom backdoors to Storm-2306, both of which appear to be part of the framework named AK47 C2 based on the shared PDB path: C:\Users\Administrator\Desktop\work\tools\ak47c2\. When executed, the program immediately hides its console window, determines the host computer name (defaulting to unknown.local if that fails), and builds a DNS‑based command‑and‑control payload. It chooses a random five-character session ID, such as H4T14, and prefixes it with 1 for task requests or 2 for result uploads (e.g., 1H4T14 or 2H4T14). Each element, such as the task/result tag, a size flag (a for “all” when the entire message fits into one request), and the computer name, is XOR‑encoded with the ASCII key “VHBD@H”, converted to hexadecimal, and concatenated with dots before being prepended to the C2 domain update.micfosoft[.]com. This what the overall query looks like: DNS TXT and MG (a mail group member record type) record lookups (DnsQuery_A) are used to transmit and retrieve data. If the C2 server is unreachable, the client simply receives error 9003 (DNS_ERROR_RCODE_NAME_ERROR). Otherwise, the response text is decoded from hex, XOR‑decrypted, and parsed for the delimiter “:::”, which separates metadata from the actual command string. Commands run under cmd.exe /c 2>&1; a built‑in directive sleep n pauses execution for n seconds. For outputs larger than 0xFF bytes, the backdoor fragments data into 63‑byte sub‑segments. Each DNS query then follows: HttpClient backdoor has the pdb path C:\Users\Administrator\Desktop\work\tools\ak47c2\httpclient-cpp\x64\Release\httpclient-cpp.pdb and uses plain HTTP instead of DNS for the C2. It is built as a 64‑bit console program that also immediately hides its window on launch. On start‑up, the malware gathers the host computer name (similar to the DNS version, it defaults to unknown.local), then builds a JSON object with the fields cmd, cmd_id, fqdn, result, and type. For a task request, the object looks like this: {"cmd":"","cmd_id":"","fqdn":" ","result":"","type":"task"} After the host executes a command, the result is sent back with type:”result”. Before transmission, the entire JSON blob is XOR‑encrypted with the ASCII key “VHBD@H”, converted to hexadecimal, and placed in the body of an HTTP POST to “/” with generic headers (Content‑Type: text/plain, Accept: */*). The C2 replies with a similarly encoded JSON where the cmd field contains the next command. The implant executes it via cmd.exe /c 2>&1 and returns the output. We identified that during these attacks, several types of ransomware were deployed simultaneously. One is regular LockBit Black, and the second uses the.x2anylock extension. This extension was later used by the Warlock ransomware operator, mentioned in Microsoft’s report on the SharePoint exploitation. The Warlock ransom note is usually saved as How to decrypt my data.txt and looks like this: Figure 3 – Warlock Group ransom note. The ransom notes for all ransomware strains deployed by Storm-2603 are named How to decrypt my data.log (x2anylock) or .README.txt (LockBit Black) and have the same short content: Your decrypt ID: [redacted] Tox ID Support: 3DCE[redacted] Email Support: [redacted]@proton.me,[redacted]@proton.me,[redacted]@proton.me You can contact us in email or qtox. This ransom note’s name How to decrypt my data.log appeared in a recent LinkedIn post by Huntress, describing the case where multiple ransomware families were deployed together against the same target. While not a new tactic, this approach is rarely observed among established ransomware groups. An important part of the infection package described earlier is called Antivirus Terminator. It is a custom command line tool abusing a third-party signed legitimate driver to kill processes. From what we can see, it’s been in the wild since at least late 2024. The tool requires administrative privileges on the infected machine. The screenshot below shows how the listing is displayed in the console when the tool is run without parameters: Figure 4 – Antivirus Terminator supported arguments when run without parameters. The tool first creates a service called ServiceMouse, where the path to the service binary file is ServiceMouse.sys from the package. Next, the tool communicates with the installed service via IO control code 0x99000050, which is responsible for killing processes. The tool also has more capabilities, like deleting files and uninstalling drivers, and these use different IO control codes (0x990000D0 and 0x990001D0). Figure 6 – Antivirus Terminator kills process using third-party driver. The supplied third-party driver is a legitimate and signed component of Antiy System In-Depth Analysis Toolkit, originally named AToolsKrnl64.sys. The toolkit was developed by Antiy Labs, a Chinese security vendor, and features a graphical user interface that allows users, among others, to interact with and manipulate processes. The ability to kill processes is the most important feature which is abused by threat actors in this particular case. Figure 7 – Antiy System In-Depth Analysis Tookit GUI. The following piece of code in the driver handles the IO control code 0x99000050 mentioned above: Figure 8 – IO control code processing in the Antiy driver. The second function is the piece of code responsible for killing a process with a given PID. In this report we analyze Storm-2603, a relatively new threat actor first mentioned by Microsoft during investigations into the “ToolShell” campaign targeting SharePoint servers. While some of the exploitation activity was tied to known Chinese APT groups, Storm-2603 stood out as a previously undocumented group linked to ransomware deployment. By examining infrastructure indicators shared in public reporting, we were able to connect this actor to earlier campaigns involving LockBit Black and Warlock/X2anylock ransomware, dating back to at least March 2025. These earlier attacks used similar infrastructure and tools, including DNS tunneling and HTTP-based backdoors. Interestingly, multiple ransomware variants were deployed in the same attack. This behavior, along with the overlap in techniques, helps us better understand how Storm-2603 operates “The Turkish Rat” Evolved Adwind in a Massive Ongoing Phishing Campaign Check Point Research Publications August 11, 2017 “The Next WannaCry” Vulnerability is Here Check Point Research Publications March 12, 2026 “Handala Hack” – Unveiling Group’s Modus Operandi SUBSCRIBE TO CYBER INTELLIGENCE REPORTS We value your privacy! BFSI uses cookies on this site. We use cookies to enable faster and easier experience for you. By continuing to visit this website you agree to our use of cookies.
2 shared
Aug 8, 2025