ClickFix Exploit Uses Steganography for Malware Delivery

26 Nov 2025

ClickFix exploits deceive users into running mshta commands, initiating a multi-stage malware delivery that often leads to the Rhadamanthys infostealer.

Multi-Stage Execution

The attack begins when users are prompted by malicious webpages to execute an mshta command. This command downloads an obfuscated script utilizing hex-encoded URLs and rotated paths. The script then executes further obfuscated PowerShell commands.

Subsequently, PowerShell decrypts and loads a .NET assembly loader. This loader employs custom steganography to extract shellcode from PNG images, embedding payload bytes within pixel colors, primarily the red channel.

Advanced Techniques

The shellcode is injected into trusted processes via memory techniques, such as VirtualAllocEx and WriteProcessMemory. Final payloads often include infostealers like LummaC2 and Rhadamanthys.

This method of hiding malware in image files makes detection challenging, as the malware is reconstructed entirely in memory from seemingly innocuous files.

Preventive Measures

To stay protected, users should avoid following webpage prompts that urge command executions. Running scripts or commands from untrusted sources is discouraged, and manual typing is preferred over copy-pasting commands.

  • Maintain updated security software with web protection
  • Verify instructions through official support channels
  • Educate yourself on emerging attack techniques

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6653954
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1389523
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
550434
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
460318
downloads

News and reviews for Desktop Windows

Decious Deckbuilders 2 Bundle Offers Eight Games at Discount

The Decious Deckbuilders 2 Humble Bundle offers eight discounted deckbuilding games until 2025-12-12.

Read more

Release Paralives in May 2026, Gameplay Video Unveiled

Paralives delayed to May 2026, unveiling a detailed gameplay video showcasing simulation depth. Live Mode improvements promise engaging user experience.

Read more

Death Stranding 2 PC Version Potentially Revealed by ESRB

A potential PC release of Death Stranding 2 was hinted at by an ESRB leak, suggesting changes in PlayStation's strategy.

Read more

Wildgate by Former StarCraft Devs Offers Fresh Gaming Experience

Moonshot Games' Wildgate, released 2025-11-26, brings unique mechanics and strategic balance. Now half-price on Steam.

Read more

Mounts Mayhem Update Hits Minecraft on 2023-12-09

Mojang's Mounts Mayhem update launches for Minecraft Java and Bedrock with new mounts, weapons, and features.

Read more

PowerDisplay to Simplify Multi-Monitor Setup on Windows 11

PowerToys introduces PowerDisplay for better multi-monitor control on Windows 11, expected January 2026.

Read more

Launch Announced for Pathbreakers: Roaming Blades RPG

6 Eyes Studio unveils Pathbreakers, a turn-based RPG in Stormtossed Isle with mercenary leads. Featuring mod support, it promises diverse gameplay.

Read more

Release Updated Elemental Evil on Steam This December

Sneg will release an upgraded Elemental Evil game on Steam on 2023-12-10, featuring enhanced gameplay and numerous improvements.

Read more

Sublustrum Set for 2026 PC and Console Release

Sublustrum, a 3D reimagining of Outcry, releases fall 2026 in multiple languages.

Read more

Judges Urge Halt of Trellix Antivirus Rollout

Bulgarian judges demand pausing Trellix deployment over data protection fears.

Read more