Multiple threat reports describe ClickFix-style social engineering and related Windows loader chains that trick users into launching malicious PowerShell or staged binaries, culminating in memory-resident malware. In one campaign, a fake CAPTCHA coerces victims into running PowerShell that fetches a first-stage script, injects a .NET loader into powershell.exe, and launches a Donut 0.9.3 shellcode package entirely in memory to deploy an infostealer targeting Firefox data, Chromium cookies, and screenshots. Separate reporting also tied ClickFix activity to HijackLoader-based stealer delivery and to a campaign abusing signed Mozilla Firefox binaries for DLL sideloading of KongTuke, with Rust-based DLL variants handling loading, persistence, and command-and-control.
Another analyzed infection chain used a heavily obfuscated batch-script loader that rebuilt embedded payloads, renamed PowerShell to HDVz.exe, staged files under C:\ProgramData\IntelDriver, and created a scheduled task for logon persistence before injecting Donut shellcode into explorer.exe. That malware tampered with AMSI and ETW, used a custom memory marker DE AD BE CA FE BA EF to avoid duplicate injection, and sent execution notifications through the Telegram Bot API while attempting outbound communication to 167.88.167.9:8356. Across the reporting, the common pattern is the use of trusted binaries, in-memory execution, shellcode loaders, and evasive tradecraft to steal data or maintain access while minimizing disk artifacts and frustrating endpoint detection.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Gurucul reported that recent weeks had seen increased ClickFix social-engineering activity delivering KongTuke through DLL sideloading with legitimate Mozilla Firefox binaries. The report identified Rust-based DLL variants for loading, persistence, and command-and-control, along with DGA-based HTTPS infrastructure.
Aryaka Threat Research Lab analyzed a Windows malware campaign using an obfuscated batch-script loader that reconstructs payloads, renames PowerShell to HDVz.exe, persists via a scheduled task, and injects Donut shellcode into explorer.exe. The report also highlighted AMSI and ETW tampering, Telegram execution notifications, and outbound TCP communication to 167.88.167.9:8356.
Neso published the second part of its analysis of a live stealer campaign involving ClickFix and HijackLoader. No further dated event details are provided in the reference content.
Neso published the first part of its analysis of a live stealer campaign involving ClickFix and HijackLoader. No further dated event details are provided in the reference content.
JMP-ESP analyzed a new multi-stage ClickFix campaign that used mshta, VBScript, PowerShell, and repeated Donut-loader stages to deploy malware classified by VirusTotal as a Lumma variant. The chain ultimately injected into dllhost.exe and deployed ChromElevator to steal Chromium browser data, with AMSI, WLDP, and ETW patching plus Telegram Bot API exfiltration.
Swiss Post Cybersecurity reported a multi-stage ClickFix campaign in which a fake CAPTCHA tricked victims into running PowerShell, leading to an in-memory Donut-based loader and a bespoke infostealer. The report documented browser-data theft, screenshot capture, and exfiltration to 31.177.108.17:12345.
K7 Labs documented a malware delivery campaign in which FakeCaptcha/ClickFix pages, increasingly reached through malvertising, tricked users into running a copied PowerShell command that launched a multi-stage mshta, JavaScript, and PowerShell chain. The analysis said the chain commonly delivered Emmenhtal and in most observed cases ended with Lumma Stealer loaded in memory as a .NET assembly.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
community.gurucul.com
Open sourcearyaka.com
Open sourcejmp-esp.org
Open sourceswisspost-cybersecurity.ch
Open sourcelabs.k7computing.com
Open sourcereversethemalware.blogspot.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.