ClickFix Exploit Uses Steganography for Malware Delivery

26 Nov 2025

ClickFix exploits deceive users into running mshta commands, initiating a multi-stage malware delivery that often leads to the Rhadamanthys infostealer.

Multi-Stage Execution

The attack begins when users are prompted by malicious webpages to execute an mshta command. This command downloads an obfuscated script utilizing hex-encoded URLs and rotated paths. The script then executes further obfuscated PowerShell commands.

Subsequently, PowerShell decrypts and loads a .NET assembly loader. This loader employs custom steganography to extract shellcode from PNG images, embedding payload bytes within pixel colors, primarily the red channel.

Advanced Techniques

The shellcode is injected into trusted processes via memory techniques, such as VirtualAllocEx and WriteProcessMemory. Final payloads often include infostealers like LummaC2 and Rhadamanthys.

This method of hiding malware in image files makes detection challenging, as the malware is reconstructed entirely in memory from seemingly innocuous files.

Preventive Measures

To stay protected, users should avoid following webpage prompts that urge command executions. Running scripts or commands from untrusted sources is discouraged, and manual typing is preferred over copy-pasting commands.

  • Maintain updated security software with web protection
  • Verify instructions through official support channels
  • Educate yourself on emerging attack techniques

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7202604
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1627208
downloads
WinRAR

WinRAR

Streamline file management with fast compression, secure your documents, and save space.

5
735 reviews
697352
downloads
Minecraft

Minecraft

Shape environments, explore vast worlds, and survive against monsters with endless creativity.

5
750 reviews
485859
downloads

News and reviews for Desktop Windows

007 First Light Reveals PC Specs and NVIDIA Collaboration

IO Interactive's 007 First Light announces detailed PC specs and NVIDIA features, enhancing gameplay visuals.

Read more

Free File Managers for Windows Outperform File Explorer

Explore three free Windows file managers, Total Commander, OneCommander, and FileVoyager, offering enhanced features over File Explorer.

Read more

Copilot Vision Adds App Analysis to Windows 11 Taskbar

Microsoft's Copilot Vision now analyzes apps via the Windows 11 taskbar, offering suggestions based on content. Available for all PCs.

Read more

StarRupture Enters Steam Early Access with Unique Survival Mechanisms

StarRupture, from Creepy Jar, hits Steam Early Access, challenging players with survival tactics in extreme conditions.

Read more

Escape From Tarkov Tightens Terminal Mission Rules

Escape From Tarkov's Terminal mission sees stricter extraction rules, diverging from player requests for a simplified process.

Read more

Warhorse Studios Explores Unreal Engine for New Projects

Warhorse Studios hints at new projects with Unreal Engine, shifting away from CryEngine. Potential for diverse settings.

Read more

Wildgate and Total War: Three Kingdoms Free on Epic Games Store

Wildgate, an extraction shooter by Moonshot Games, is free on Epic Games Store until 2024-01-08. Claim now for an exciting gaming experience.

Read more

StarRupture Offers Early Access Discount for 2026 Launch

StarRupture by Creepy Jar launches in early access on 2026-01-06 with a 20% discount.

Read more

Hytale's World Generation V2 Set to Transform Gameplay

Hytale's new world generation debuts soon, offering players customizable, procedural landscapes. Impact expected in gaming innovation.

Read more

FlyOOBE Enhances AI Removal in Windows 11

FlyOOBE updates expand AI debloating options for Windows 11, introducing version 2.4 with new features and user risks.

Read more