A ClickFix cluster: Observed activity from recent ClickFix campaigns
Description
Multiple ClickFix malware campaigns have been identified using three delivery methods: MSI packages with DLL sideloading, NodeJS-executed JavaScript, and Python 3.5 payload execution. These campaigns use aggressive social engineering, including phone calls directing victims to compromised WordPress sites. Post-compromise activities include extensive system discovery and Active Directory enumeration. The campaigns share infrastructure and tactics linked to the Lorem Ipsum malware family and Vanilla Tempest adversary, with potential ransomware deployment as a final goal.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The ClickFix cluster consists of multiple malware campaigns employing three distinct delivery mechanisms that share common traits such as DLL sideloading, consistent file-naming conventions, and command-and-control dead drops. The first campaign uses remotely hosted MSI installers containing legitimate software to sideload malicious DLLs. The second campaign leverages NodeJS to run JavaScript files, while the third uses Python 3.5 to hide and execute payloads. All campaigns originate from ClickFix-themed lures and employ aggressive social engineering tactics, including direct phone contact that guides victims to compromised WordPress sites. After initial compromise, the attackers perform extensive discovery commands and Active Directory enumeration. The infrastructure and tactics overlap with the Lorem Ipsum malware family and Vanilla Tempest operations, indicating a potential ransomware deployment objective.
Potential Impact
Successful exploitation leads to system compromise through DLL sideloading, script execution, and payload concealment. Attackers gain extensive visibility into the victim environment via discovery commands and Active Directory enumeration, enabling further lateral movement or data collection. The campaigns may culminate in ransomware deployment, posing significant risk to confidentiality, integrity, and availability of affected systems.
Defensive Guidance
No official patches or fixes are applicable as this is a malware campaign rather than a software vulnerability. Mitigation should focus on user awareness to resist social engineering, blocking known malicious domains and hashes associated with the campaigns, and monitoring for indicators of compromise such as suspicious MSI installations, NodeJS and Python script executions, and unusual Active Directory queries. Organizations should also secure WordPress sites to prevent compromise used in these campaigns.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://fieldeffect.com/blog/clickfix-cluster-observed-activity-recent-campaigns"]
- Adversary
- Vanilla Tempest
- Pulse Id
- 6a8cb558cf3bdab6268fd52f
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domaineditdocumentfree.com | — | |
domainopendocumentonline.com | — | |
domainnewpopularimages.com | — | |
domaincloudbreachdetection.com | — | |
domaincooldogshistory.com | — | |
domainbeastcloudsecurity.com | — | |
domainbestpopularimages.com | — | |
domainpeekyourphoto.com | — | |
domainphotocategories.com | — | |
domainseephotoalbum.com | — | |
domaintopimagechecker.com | — | |
domaintopphotoalbum.com | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash2104e7018aa9fd2507cc036e2aa4ff80e613a156ab1cb78604773d447298a854 | — | |
hash32b1f676dd98449a47ba671c4bdd6269e070a8fb349d1c02404a3784b4d4c77f | — | |
hash4cbaac416954408f37ebcc97ba4c08facef86c20b3cbec9324a4932b5fc1acbb | — | |
hash6304d348b45154b4d6d7c3f1176304d2c0112d23c08a0178fa6d0b74a967a85d | — | |
hash72cd20b5a398febd6868e1b88e86afb5a8163969b8cd7bb7895f52fc9ea4424d | — | |
hash7545d737202df6d90118e04a963acbd1b16a1f4e0a1c173bef7ab9489efdcd16 | — | |
hashd092ac012ccb75416802ee697a5f65b2c0545d047a20869c53124db9e37f3dcd | — | |
hashf80d8f5950086a053c68dcdcb5902f2ad8b8e4fcf400855c316aef09fe0f55e5 | — |
Threat ID: 6a8d73d1acd9273b490ff671
Added to database: 08/25/2026, 10:52:01 UTC
Last enriched: 09/10/2026, 20:04:23 UTC
Last updated: 10/04/2026, 08:48:14 UTC
Views: 153
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.