๐จ ๐๐ฒ๐ด๐ถ๐๐ถ๐บ๐ฎ๐๐ฒ ๐๐ฎ๐ ๐ช๐ฒ๐ฏ๐๐ถ๐๐ฒ๐ ๐๐ฏ๐๐๐ฒ๐ฑ ๐ณ๐ผ๐ฟ ๐๐ถ๐น๐ฒ๐น๐ฒ๐๐ ๐ ๐ฎ๐น๐๐ฎ๐ฟ๐ฒ ๐๐ฒ๐น๐ถ๐๐ฒ๐ฟ๐: ๐๐ฒ๐๐ฒ๐ฐ๐ ๐๐ ๐๐ฎ๐ฟ๐น๐
Weโre tracking widespread #ClickFix activity using compromised legitimate websites to deliver fileless malware, lowering suspicion and delaying detection.
โ ๏ธ Finance, banking, healthcare, manufacturing, and tech are among the most exposed industries.
โ๏ธ The activity looks low-risk until fileless execution and outbound C2 traffic are already established. Attackers inject a lightweight inline JavaScript loader into compromised sites, which retrieves a second-stage payload directly into the victimโs browser from external infrastructure.
The attack chain blends into normal web traffic, relies on PowerShell and in-memory execution, and later shifts C2 communication into the legitimate system process svchost.exe, making malicious activity harder to distinguish from routine system behavior for SOC and MSSP teams.
โก๏ธ #ANYRUN Sandbox helps teams validate suspicious activity faster and contain fileless attacks before they escalate. Analysts can observe the full execution chain in real time:
Inline JS loader โก๏ธ User-executed PowerShell (IEX/IRM) โก๏ธ Hidden second-stage PowerShell and loader retrieval โก๏ธ Fileless in-memory execution inside powershell.exe โก๏ธ Follow-on .NET payload delivery โก๏ธ svchost.exe injection โก๏ธ Custom TCP C2 ๐จ
๐จโ๐ป Learn how #ANYRUN helps security teams detect complex threats and contain incidents faster: https://any.run/enterprise/?utm_source=mastodon&utm_medium=post&utm_campaign=clickfix_fileless_malware&utm_content=linktoenterprise&utm_term=200526
๐ Scale your SOC with solutions trusted by 74 Fortune 100 companies. Get an exclusive 10th anniversary deal for your team: https://app.any.run/plans/?utm_source=mastodon&utm_medium=post&utm_campaign=clickfix_fileless_malware&utm_content=linktoplans&utm_term=200526
IOCs:
/jsrepo?rnd=
/teamrepo?rnd=
ntdnewtds[.]shop
dnsnewtds[.]shop
sdntds[.]shop
newtdsone[.]shop
nttdss[.]shop
Dntds[.]shop
178[.]16[.]52[.]232
158[.]94[.]208[.]92
158[.]94[.]208[.]104
91[.]92[.]243[.]161

