ClickFix Exploit Uses Steganography for Malware Delivery

26 Nov 2025

ClickFix exploits deceive users into running mshta commands, initiating a multi-stage malware delivery that often leads to the Rhadamanthys infostealer.

Multi-Stage Execution

The attack begins when users are prompted by malicious webpages to execute an mshta command. This command downloads an obfuscated script utilizing hex-encoded URLs and rotated paths. The script then executes further obfuscated PowerShell commands.

Subsequently, PowerShell decrypts and loads a .NET assembly loader. This loader employs custom steganography to extract shellcode from PNG images, embedding payload bytes within pixel colors, primarily the red channel.

Advanced Techniques

The shellcode is injected into trusted processes via memory techniques, such as VirtualAllocEx and WriteProcessMemory. Final payloads often include infostealers like LummaC2 and Rhadamanthys.

This method of hiding malware in image files makes detection challenging, as the malware is reconstructed entirely in memory from seemingly innocuous files.

Preventive Measures

To stay protected, users should avoid following webpage prompts that urge command executions. Running scripts or commands from untrusted sources is discouraged, and manual typing is preferred over copy-pasting commands.

  • Maintain updated security software with web protection
  • Verify instructions through official support channels
  • Educate yourself on emerging attack techniques

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6755217
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1435298
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
583203
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
464056
downloads

News and reviews for Desktop Windows

Kill Joy Game Announced for PC: A Unique System-driven Experience

Kill Joy, a unique systems-driven exploration game, announced for PC. Players escape deceptive worlds by making creatures cry.

Read more

Epic Games Store Offers Free Games: Limited Time Access

Epic Games Store presents Free Games this December: The Darkside Detective and Jackbox Party Pack 4 for one week.

Read more

Sony Partners with Bad Robot for New Co-op Shooter

Sony teams up with Bad Robot Games for a co-op shooter on PS5 & PC, led by Mike Booth.

Read more

Microsoft Patches Windows LNK Zero-Day Exploit

Microsoft addressed a critical Windows LNK vulnerability in 2025-10; impact are worldwide malware risks.

Read more

Helldivers 2 Install Size Reduced to 23GB in Beta

Arrowhead optimizes Helldivers 2 on PC, reducing installation size from 154GB to 23GB. New beta shows improved load speeds and space efficiency.

Read more

Prologue Expands with Three DLCs but No Wildlife

Prologue creator Brendan Greene confirms three new DLCs, focusing on game depth but ruling out animal additions.

Read more

Destiny 2's Renegades Expansion Boosts Player Count on Steam

Destiny 2's Renegades expansion led to a player spike on Steam. Despite Star Wars themes, numbers remain below past peaks.

Read more

Microsoft Fixes LNK Vulnerability Exploited Since 2017

Microsoft patched the long-standing LNK security flaw in Windows as part of the November 2025 update, impacting user security.

Read more

Highlights from PC Gaming Show: Most Wanted 2025 Countdown

PC Gaming Show: Most Wanted 2025 on December 4 reveals top PC games with new trailers and announcements. Anticipated by gamers and industry experts.

Read more

Microsoft Alters LNK File Behavior to Tackle Vulnerability

Microsoft changes LNK file handling in response to exploited vulnerability CVE-2025-9491, affecting multiple cybercrime groups.

Read more