216.73.217.22

Proactive ClickFix Threat Hunting with Hunt.io

· Published 04/04/2025 07:07 · Modified 04/04/2025 17:02

Export JSON

Essential information

Published
04/04/2025 07:07
Modified
04/04/2025 17:02
Tags
2025-04-04 browser-based attacks captcha clickfix clipboard hijacking credential-theft cryptbot information stealers lumma stealer malware delivery powershell threat hunting
Related entities
19 techniques (mitre), 2 malware

Description

is a browser-based delivery technique that uses deceptive prompts and to trick users into executing malicious commands. Cybercriminals and advanced actors employ this method to deploy malware, primarily . The technique involves luring users with fake system alerts or challenges, then silently staging payloads for execution. The article describes how Hunt.io's research team used custom queries to identify web infrastructure associated with delivery, uncovering multiple live domains serving malicious content. Examples include a Bitcoin-themed domain posing as Cloudflare WAF to deliver Lumma and malware, a page targeting Zoho Office Suite credentials, and a compromised website abusing . The report emphasizes the growing traction of as a low-friction method for and credential harvesting.

External references