ClearFake ClickFix Intrusion: WebDAV-Delivered Multi-Stealer Chain with Blockchain-Resolved Backdoor and DLL Side-Loading
Source report →Vega's CTI team investigated a ClickFix based intrusion chain, independently confirmed across four separate sandbox detonations tied to a single delivery infrastructure. Victims are shown a fake verification prompt instructing them to paste a command into the Windows Run dialog. The pasted command invokes the Program Compatibility Assistant (pcalua.exe) to proxy launch PowerShell, which then uses a hidden WMI process creation call to spawn the command interpreter. That interpreter mounts a WebDAV share over HTTPS from a subdomain of the delivery infrastructure and loads a disguised file through rundll32 by raw ordinal export, completing a wrapper engineered specifically to defeat detections that rely on normal parent-child process relationships.
The retrieved loader unpacks Vidar Stealer in memory, then stages two further payloads: a signed third party runtime launcher, placed in a temporary folder next to an oversized, trojanized copy of its own dependency library, executes attacker code through DLL side loading, and a fresh instance of the signed build tool MSBuild.exe runs a SectopRAT or ArechClient2 remote access trojan entirely in memory. Persistence is established by copying ZigCryptoStealer into a randomly named folder and pointing a matching autorun registry value at it, so it relaunches on every logon. One of the payloads resolves its command and control configuration through EtherHiding, reading a public blockchain smart contract instead of a domain, which survives takedowns since updates only require a low cost transaction rather than new infrastructure.
To decrypt the browser's own stored passwords and cookies, a fresh instance of MSBuild.exe launches the victim's real Chrome or Edge browser against a disposable profile with sandboxing disabled, and the intrusion then reads those secrets straight from the profile on disk. Stolen data is exfiltrated over the same connection Vidar already uses for command and control, and rundll32.exe resolves that same C2 domain through DNS over HTTPS instead of a normal DNS lookup.
The delivery infrastructure sits behind Cloudflare and reuses a small set of TLS certificates across dozens of ordinary looking apex domains, each with its own randomly named subdomain serving the payload. Pivoting from one delivery domain through shared certificate and certificate transparency data surfaced the full cluster, confirming that every apex domain's own name is also reused as a subdomain label under a single attacker owned zone, fg777-srv[.]top, and that targeting is opportunistic rather than sector specific.
IOCs (123)
Scan your environment for IOCs →DOMAIN 119
fg777-srv.toppatxisdublin.comjetourmexico.comlunabybodyshaping.comdbqu.highkickstkd.comuumt.opulentbeautybarllc.comzvuy.comptonanimalrescue.comljxh.patxisdublin.combikertlane.combittersweetkennel.combolesfarms.comborrender.comburritodelight.comcardanaircraft.orgcheaperthan-dirt.comcleantruckchecksac.comclosedfistllc.comcolg1.orgcomptonanimalrescue.comconcretewestgj.comcorgiwarehouse.comcustomhomebuildersplainfield.comdermatologycongress.orgdermexcel.netdiamonddumpsterrental.netdivanailsachse.comdomirunway.comeconomywindowsparts.comeverestpointnorthglenn.orgezgarageautorepairtx.comnurtured-in-nature.comfinovestpedia.comfit2leadconference.comfontanayoga.comfrisbeeburgerllc.comgobgem.comgoodlifelakerentals.comhairbyniki.comhayleymarienorman.comhighkickstkd.comhurtigegevinster.comjenslittlerugrats.orgkaltourusa.comletstalkrocks.comlnlsealcoating.comloganlooneyresume.commechanic-on-site.commissavws.netmonicarobles.orgopulentbeautybarllc.comordereltacofeliz.compacesettershomehealth.compolarstartire.comricardotaxiservices.comridgerenovation.comriggsjacksboro.comrspmpanyabungan.comscissormasterstanningsalon.comsdcwoodcraft.comseamsnstitches.comshawnmaltipoopuppies.comshopsoleilcollective.comslepsluzbaublizini.comsnydersflowershop.comsolucionesintegralesgiraldo.comspacedecorideas.comspencershorttexas.comspringhillcommons.comstable-virtual-camera.comstudiofourfitnessnv.comtaqueriadonamariaky.comthebrandus.comthechildrencomefirst.orgthelegalexpertise.comthetokestudio.comtrueamatuermodels.comupthesmokee.comvitalmcallen.comwellcome-c-store.comwhitelaneint.comwindhorseevents.comaimhighbasketballcamp.comalliancecarerx.comapk.yumaneed.comashleynewsome.comatwaternaz.comauraapp.orgbbibeautyshop.combedfordrealtycorp.combibisafricanhairbraids.combreezybowlhouston.combreezybowlstlouis.comdcsplumb.comdesign.yumaneed.comenjoyflowersbusiness.comglendoradentalcenter.comhuman.yumaneed.cominfinitymakeoverstudio.cominternationaltreeservice.commatecfilterpress.commcbridervpark.commobile.breezybowlhouston.commobile.yumaneed.commodelstvseries.comproject.yumaneed.comprotransportationservice.comrohamsport.comrsudtarutung.comseattle-immigrationlawyer.comstore.ridgerenovation.comstory.yumaneed.comtaxi88.ashleynewsome.comthehairspotsalon.comtmowersnstuff.comwss.vectorplatform.ccquorashift.ccstatic.quorashift.ccgw.portallbridge.ccxss.gumminessheap.in.netIP ADDRESS 1
45.140.14.113SHA256 FILE HASH 3
40bc68612f43cdf66737784640a706efdbdad24c0423d5e08ef47cc6ebd97ffc99279a25c028fc85747e68521fc5dee135bcfa01602fd3109cba81959db476d417d4935ddc1f05cc18861b8270d935d52fa77bda00ca3e694cdedd807a8e0d78Detections (10)
Enable detections →Connect your environment for suggestions and queries personalized to your security telemetry.
- Pcalua Proxy Execution Of Script Interpreter
- PowerShell Command Line Constructing a Hidden WMI Process Creation Call
- Rundll32 Ordinal Execution of a Non DLL Named File
- ClickFix Explorer Spawning Command Execution Proxy Binary
- MSBuild.exe Launched With No Command Line by an Untrusted Parent Process
- Non-Browser Process Connecting to Ethereum RPC
- Known Sideloading Target Library Loaded From a User Writable Directory
- Trace or ETW Logging Disabled by a .NET Process
- Non-Browser Process Launching a Real Browser with Sandboxing Disabled and a Disposable Profile