Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

A ClickFix cluster: Observed activity from recent ClickFix campaigns

0
Medium
Published: 08/24/2026 (08/24/2026, 21:19:20 UTC)
Source: AlienVault OTX General

Description

Multiple ClickFix campaigns were identified employing three distinct delivery mechanisms while sharing common characteristics including DLL sideloading, consistent file-naming conventions, and command-and-control dead drops. The first campaign used remotely hosted MSI packages containing legitimate software to sideload malicious DLLs. The second leveraged NodeJS to execute JavaScript files, while the third utilized Python 3.5 to conceal and execute payloads. All campaigns originated from ClickFix lures and employed aggressive social engineering tactics, including direct phone contact directing victims to compromised WordPress sites. Post-compromise activity included extensive discovery commands and Active Directory enumeration. Infrastructure overlap and tactics indicate connections to the Lorem Ipsum malware family and Vanilla Tempest operations, with potential ransomware deployment as the final objective.

Technical Details

Author
AlienVault
Tlp
white
References
["https://fieldeffect.com/blog/clickfix-cluster-observed-activity-recent-campaigns"]
Adversary
Vanilla Tempest
Pulse Id
6a8cb558cf3bdab6268fd52f
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domaineditdocumentfree.com
domainopendocumentonline.com
domainnewpopularimages.com
domaincloudbreachdetection.com
domaincooldogshistory.com
domainbeastcloudsecurity.com
domainbestpopularimages.com
domainpeekyourphoto.com
domainphotocategories.com
domainseephotoalbum.com
domaintopimagechecker.com
domaintopphotoalbum.com

Hash

ValueDescriptionCopy
hash2104e7018aa9fd2507cc036e2aa4ff80e613a156ab1cb78604773d447298a854
hash32b1f676dd98449a47ba671c4bdd6269e070a8fb349d1c02404a3784b4d4c77f
hash4cbaac416954408f37ebcc97ba4c08facef86c20b3cbec9324a4932b5fc1acbb
hash6304d348b45154b4d6d7c3f1176304d2c0112d23c08a0178fa6d0b74a967a85d
hash72cd20b5a398febd6868e1b88e86afb5a8163969b8cd7bb7895f52fc9ea4424d
hash7545d737202df6d90118e04a963acbd1b16a1f4e0a1c173bef7ab9489efdcd16
hashd092ac012ccb75416802ee697a5f65b2c0545d047a20869c53124db9e37f3dcd
hashf80d8f5950086a053c68dcdcb5902f2ad8b8e4fcf400855c316aef09fe0f55e5

Threat ID: 6a8d73d1acd9273b490ff671

Added to database: 08/25/2026, 10:52:01 UTC

Last updated: 08/25/2026, 13:52:47 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses