216.73.217.22

Beyond PowerShell: Analyzing the Multi-Action ClickFix Variant

· Published 23/04/2026 03:26 · Modified 27/04/2026 14:32

Export JSON

Essential information

Published
23/04/2026 03:26
Modified
27/04/2026 14:32
Tags
2026-04-23 clickfix cmdkey lolbins regsvr32 remote dll scheduled task social engineering unc path
Related entities
2 observables, 14 techniques (mitre)

Description

This analysis documents a newly observed variant that abuses native Windows utilities, specifically and , for payload delivery. Victims are socially engineered through fake CAPTCHA pages to execute a malicious command via the Windows Run dialog. The single command chains multiple actions: staging credentials using , retrieving a via from a , and executing it silently. The 64-bit DLL establishes persistence through a pulled from a remote XML file hosted on attacker infrastructure. This approach avoids traditional malware drops and leverages exclusively trusted Windows components for high stealth. The variant demonstrates continued evolution of techniques, moving beyond PowerShell to use command chaining with legitimate system tools.

External references