216.73.217.98

Threat Actors Lure Victims Into Downloading .HTA Files Using ClickFix To Spread Epsilon Red Ransomware

· Published 25/07/2025 10:29 · Modified 25/07/2025 12:37

Export JSON

Essential information

Published
25/07/2025 10:29
Modified
25/07/2025 12:37
Tags
2025-07-25 activex clickfix drive-by-download epsilon red hta files impersonation phishing quasar rat ransomware social engineering
Related entities
5 observables, 1 intrusion sets (apt), 6 techniques (mitre), 2 malware

Description

A new campaign has been discovered targeting users globally through fake verification pages. Active since July 2025, the threat actors employ tactics and impersonate popular platforms like Discord, Twitch, and OnlyFans to trick users into executing malicious . via . This method leads to silent payload downloads and deployment. The campaign uses a -themed malware delivery site, urging victims to visit a secondary page where malicious shell commands are executed. The attackers also impersonate various streaming services and use romance-themed lures. , first observed in 2021, shows some similarities to REvil in its ransom note styling but appears distinct in its tactics and infrastructure.

External references