216.73.217.174

From ClickFix to Command: A Full PowerShell Attack Chain

· Published 11/08/2025 15:29 · Modified 11/08/2025 16:12

Export JSON

Essential information

Published
11/08/2025 15:29
Modified
11/08/2025 16:12
Tags
2025-08-11 c2 communication israeli targets lateral movement obfuscation phishing powershell powershell rat rat social engineering
Related entities
1 intrusion sets (apt), 16 techniques (mitre), 1 malware, 5 others

Description

A targeted intrusion campaign impacting Israeli organizations has been identified, leveraging compromised internal email infrastructure to distribute messages. The attack uses a multi-stage, -based infection chain, culminating in the delivery of a remote access trojan (). Key characteristics include a full -based delivery chain, obfuscated payloads, evidence of , and potential overlap with MuddyWater campaigns. The attack begins with emails, progresses through a spoofed Microsoft Teams page, and uses to execute malicious commands. The payload retrieves additional data, deploys a , and establishes communication with a command and control server. The campaign demonstrates the effectiveness of living-off-the-land techniques, layered evasion, and adaptive .