{
  "name": "ClickFix Removes Your Background but Leaves the Malware",
  "slug": "clickfix-removes-your-background-but-leaves-the-malware",
  "description": "BackgroundFix masquerades as a free image-editing tool but functions as a ClickFix social engineering lure. The fake service prompts users to verify they are human, copying malicious commands to their clipboard that invoke finger.exe to retrieve additional payloads. This chain delivers CastleLoader, which subsequently drops NetSupport RAT and a custom .NET stealer dubbed CastleStealer. The loader uses reflective PE injection, API hashing, and ChaCha20-encrypted C2 communications. CastleStealer targets browser credentials, cryptocurrency wallet extensions, and Telegram sessions through DPAPI decryption and Restart Manager APIs. The campaign leverages BYOI tactics with embedded Python interpreters and multiple shellcode stages. A notable implementation flaw exists where launch method 4 references regsrv32.exe instead of the correct regsvr32.exe, causing silent failures.",
  "published": "2026-04-30T14:41:13.982000+00:00",
  "created_at": "2026-05-04T11:59:42.881000+00:00",
  "modified_at": "2026-05-04T09:59:42+00:00",
  "created_at_opencti": "2026-05-04T11:59:42.881000+00:00",
  "author": "AlienVault",
  "confidence": 100,
  "report_types": [
    "threat-report"
  ],
  "labels": [
    "castleloader",
    "clickfix",
    "netsupport rat",
    "reflective loader",
    "social engineering"
  ],
  "tags": [
    "2026-04-30",
    "castleloader",
    "clickfix",
    "netsupport rat",
    "reflective loader",
    "social engineering"
  ],
  "related_entities": {
    "indicators": [
      {
        "id": "0a86c45c-f03a-46d9-9532-36121e6717af",
        "name": "brionter.com"
      },
      {
        "id": "17c2b3d4-0c00-46c5-aee2-ba36129d017b",
        "name": "background-off.com"
      },
      {
        "id": "51f7a8eb-3cba-4603-80d2-f875ee22c62a",
        "name": "ai-scan.digital"
      },
      {
        "id": "e50f01cc-fd56-42c4-8034-bc42c5c6e4d4",
        "name": "trindastal.com"
      },
      {
        "id": "40c027b9-e12c-433a-810d-5a298d325876",
        "name": "poronto.com"
      },
      {
        "id": "18f8cb23-412c-475b-a206-33255098e9a4",
        "name": "http://poronto.com:688"
      },
      {
        "id": "252bc00f-5f11-4105-ac0f-9a6e32f945dd",
        "name": "giovettiadv.com"
      },
      {
        "id": "39d062cf-daaa-4676-817a-285be5fbe80b",
        "name": "https://brionter.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/net40.bin"
      },
      {
        "id": "0c5a5d43-1c7b-43d5-80eb-b7c97d72f98d",
        "name": "obelnamevalf.org"
      },
      {
        "id": "78bacf70-af4f-4c10-90a1-ac459324bc7d",
        "name": "38.146.28.30"
      },
      {
        "id": "ff4c5431-d05c-4237-bb2f-bb5f9d052a83",
        "name": "bg-ready.online"
      },
      {
        "id": "cda43917-4fc4-4606-a7b6-5e149dea36db",
        "name": "bg-transparency.online"
      },
      {
        "id": "f49f04a5-ad82-4eb2-bf48-951c3520da86",
        "name": "backgroundformat.online"
      },
      {
        "id": "02cd57bc-89f9-4178-986e-8a683ce227df",
        "name": "bg-go.online"
      },
      {
        "id": "a214434f-aa9b-4b80-a0aa-f825272133a2",
        "name": "https://obelnamevalf.org/OaTS7yE9zd/default"
      },
      {
        "id": "2c516396-50f8-472b-ac18-abe700707100",
        "name": "bde21d8be65d31e1c380f2daae2f73c79f3e1f4bca70fb990db6fdf6c3768c92"
      },
      {
        "id": "66e718bc-3f9b-46ed-aa65-47e35a25e0a6",
        "name": "http://giovettiadv.com:688"
      },
      {
        "id": "802e251a-8979-4b1d-b12c-fecaa80e7999",
        "name": "cheeshomireciple.com"
      },
      {
        "id": "c6719431-6a39-4b28-a638-e3ba6646c2f3",
        "name": "https://trindastal.com/8250d149-9bf8-566d-9d7d-ea925eae0a4"
      },
      {
        "id": "9b781d55-c06b-49d8-ada4-dfd128cdf7fe",
        "name": "ed391a16389234f9ebb6727711baaf3e068d7f77c465708fa3e8b7d0565d7fb9"
      },
      {
        "id": "07d17890-6949-47d2-b319-f0ad06a74d85",
        "name": "background-ready.online"
      },
      {
        "id": "96c6d164-359a-454c-85ab-062c666cfa78",
        "name": "f5dbaa09e60343f252a80d4a313a36ac11442d96b0896022d1a83744e3c11feb"
      },
      {
        "id": "36288b3d-f2f4-4ade-8c0f-5542debc84c3",
        "name": "bg-removerok.online"
      }
    ],
    "intrusion_sets": [
      {
        "id": "0f15f307-3b2b-4e0c-a86a-492c44530309",
        "name": "ClickFix",
        "slug": "clickfix"
      }
    ],
    "attack_patterns": [
      {
        "id": "16e4fc82-7c0b-4d1a-b784-b804b4df26dc",
        "name": "T1204.001"
      },
      {
        "id": "6ccd4566-e15e-40cf-b7df-4a3f737ce5cd",
        "name": "T1036.005"
      },
      {
        "id": "cf746a02-00ea-419e-912d-7b03f969c491",
        "name": "T1518.001"
      },
      {
        "id": "7dc1bc79-ccad-419e-b7c0-0f7fa8522270",
        "name": "T1055.012"
      },
      {
        "id": "b7ba0db0-7d4f-436f-8d5f-c431d690b048",
        "name": "T1555.003"
      },
      {
        "id": "667462db-9031-48eb-893a-05d35f9330a7",
        "name": "T1056.001"
      },
      {
        "id": "c9ee9b30-ba84-4c24-95e9-e8242d42af3f",
        "name": "T1071.001"
      },
      {
        "id": "32b33067-6566-4b8d-be80-e96f765d84de",
        "name": "T1059.001"
      },
      {
        "id": "6b2e0999-c7e8-4662-94ac-19aa8520ee46",
        "name": "T1059.003"
      },
      {
        "id": "97d377d8-89c7-48f8-a79f-0f48bd60df74",
        "name": "T1005"
      },
      {
        "id": "0c836307-129e-4ff7-a532-180c633cacba",
        "name": "T1027"
      },
      {
        "id": "0192fd78-09e3-4fe4-a9d3-38a7137e15fa",
        "name": "T1055.002"
      },
      {
        "id": "b7c6c1ad-f183-4128-8427-3891029c73dc",
        "name": "T1539"
      },
      {
        "id": "5999052b-e9ae-49e8-9235-d9bf975c22af",
        "name": "T1547.001"
      },
      {
        "id": "05ac27d4-58d0-44b2-a984-cd5aefd1f7f9",
        "name": "T1497.001"
      },
      {
        "id": "14660ccf-ca6b-42f6-8bca-e1b7a04650b3",
        "name": "T1573.001"
      },
      {
        "id": "0156fcda-e385-4662-b388-086c3e16feec",
        "name": "T1140"
      },
      {
        "id": "8e0fea81-4d54-4e88-a7dd-3aa8b26558ed",
        "name": "T1113"
      }
    ],
    "malware": [
      {
        "id": "e77c0ea5-60eb-4814-82ca-e2553343c1c9",
        "name": "CastleLoader",
        "slug": "castleloader"
      },
      {
        "id": "afe6e03e-de3e-4de8-9d25-0598bb953e86",
        "name": "CastleStealer",
        "slug": "castlestealer"
      },
      {
        "id": "4b31677e-de15-4b9e-a87a-e6e1c18883d4",
        "name": "NetSupport RAT",
        "slug": "netsupport-rat"
      }
    ],
    "observables": [
      {
        "id": "fb63930b-38d8-4f6d-92b5-d214f6455f19",
        "name": "background-ready.online"
      },
      {
        "id": "0ed7f449-9f55-42b8-afbb-8315e27a5db9",
        "name": "obelnamevalf.org"
      },
      {
        "id": "3990a30d-723a-4b21-9024-f764841187a0",
        "name": "giovettiadv.com"
      },
      {
        "id": "34f08d76-e20c-4ed6-a33c-e4be7bf4845f",
        "name": "cheeshomireciple.com"
      },
      {
        "id": "a3d73db2-e24f-4347-811b-ba2bdf05de2e",
        "name": "background-off.com"
      },
      {
        "id": "2ddedde5-6e36-4b04-84d0-902b93395f63",
        "name": "bg-go.online"
      },
      {
        "id": "2421ad9c-2054-4f1e-8eea-72569ef77939",
        "name": "bg-transparency.online"
      },
      {
        "id": "97607656-192c-40ec-84f9-ac1cf86e807e",
        "name": "bg-ready.online"
      },
      {
        "id": "c55712ac-eb2e-4d58-9f9a-222d5463d780",
        "name": "backgroundformat.online"
      },
      {
        "id": "2e8fce4e-0333-4c5f-8432-42423e20a89f",
        "name": "ai-scan.digital"
      },
      {
        "id": "d87ef4a8-9615-4e7c-96d1-65539000ae27",
        "name": "brionter.com"
      },
      {
        "id": "0755f9b5-9f6f-4352-8610-0e20bf870ae9",
        "name": "poronto.com"
      },
      {
        "id": "aab74341-f2ac-463d-866c-9f5011296e1f",
        "name": "trindastal.com"
      },
      {
        "id": "d4612fa1-3d94-4f39-b645-739be39440fd",
        "name": "bg-removerok.online"
      },
      {
        "id": "f6edee19-e3ae-4711-b87f-1a40cc35d6c5",
        "name": "38.146.28.30"
      },
      {
        "id": "84e7b045-9b76-492a-96ee-2a42e322c894",
        "name": "https://obelnamevalf.org/OaTS7yE9zd/default"
      },
      {
        "id": "1cd09207-1806-4f94-86a8-5a2620b50ab4",
        "name": "http://poronto.com:688"
      },
      {
        "id": "82fceae4-6886-44b7-a5b8-3f19b34f5309",
        "name": "https://trindastal.com/8250d149-9bf8-566d-9d7d-ea925eae0a4"
      },
      {
        "id": "945fb73d-98a5-4696-9068-3a549026215c",
        "name": "https://brionter.com/4ba0af68-0037-5f6e-afd1-64f89fc0f554/net40.bin"
      },
      {
        "id": "edff0b80-1709-4786-b56c-82ae94cb3a95",
        "name": "http://giovettiadv.com:688"
      },
      {
        "id": "",
        "name": "bde21d8be65d31e1c380f2daae2f73c79f3e1f4bca70fb990db6fdf6c3768c92"
      },
      {
        "id": "",
        "name": "ed391a16389234f9ebb6727711baaf3e068d7f77c465708fa3e8b7d0565d7fb9"
      },
      {
        "id": "",
        "name": "f5dbaa09e60343f252a80d4a313a36ac11442d96b0896022d1a83744e3c11feb"
      }
    ],
    "others": [
      {
        "id": "",
        "name": "brionter.com"
      },
      {
        "id": "",
        "name": "background-off.com"
      },
      {
        "id": "",
        "name": "ai-scan.digital"
      },
      {
        "id": "",
        "name": "trindastal.com"
      },
      {
        "id": "",
        "name": "poronto.com"
      },
      {
        "id": "",
        "name": "giovettiadv.com"
      },
      {
        "id": "",
        "name": "obelnamevalf.org"
      },
      {
        "id": "",
        "name": "bg-ready.online"
      },
      {
        "id": "",
        "name": "bg-transparency.online"
      },
      {
        "id": "",
        "name": "backgroundformat.online"
      },
      {
        "id": "",
        "name": "bg-go.online"
      },
      {
        "id": "",
        "name": "cheeshomireciple.com"
      },
      {
        "id": "",
        "name": "background-ready.online"
      },
      {
        "id": "",
        "name": "bg-removerok.online"
      }
    ]
  },
  "external_refs": [
    {
      "id": "b797173a-c413-490b-ab2c-22f01d62e80c",
      "standard_id": "external-reference--6292712e-cfd9-5cfc-b625-a33657e8dbe0",
      "entity_type": "External-Reference",
      "source_name": "AlienVault",
      "description": null,
      "url": "https://www.huntress.com/blog/clickfix-castleloader-backgroundfix",
      "hash": null,
      "external_id": null,
      "created": "2026-05-04T11:59:40.943Z",
      "modified": "2026-05-04T11:59:40.943Z",
      "createdById": null
    },
    {
      "id": "ec60d3fd-18c2-402b-b94b-5ae4eb170484",
      "standard_id": "external-reference--b19e2865-aaf9-5f63-8206-56404de95c01",
      "entity_type": "External-Reference",
      "source_name": "AlienVault",
      "description": null,
      "url": "https://otx.alienvault.com/pulse/69f36a0940fe2fa665ebe32e",
      "hash": null,
      "external_id": "69f36a0940fe2fa665ebe32e",
      "created": "2026-05-04T11:59:40.919Z",
      "modified": "2026-05-04T11:59:40.919Z",
      "createdById": null
    }
  ]
}