← All briefs
high July 28, 2026

ClearFake ClickFix Intrusion: WebDAV-Delivered Multi-Stealer Chain with Blockchain-Resolved Backdoor and DLL Side-Loading

Source report →

Vega's CTI team investigated a ClickFix based intrusion chain, independently confirmed across four separate sandbox detonations tied to a single delivery infrastructure. Victims are shown a fake verification prompt instructing them to paste a command into the Windows Run dialog. The pasted command invokes the Program Compatibility Assistant (pcalua.exe) to proxy launch PowerShell, which then uses a hidden WMI process creation call to spawn the command interpreter. That interpreter mounts a WebDAV share over HTTPS from a subdomain of the delivery infrastructure and loads a disguised file through rundll32 by raw ordinal export, completing a wrapper engineered specifically to defeat detections that rely on normal parent-child process relationships.

The retrieved loader unpacks Vidar Stealer in memory, then stages two further payloads: a signed third party runtime launcher, placed in a temporary folder next to an oversized, trojanized copy of its own dependency library, executes attacker code through DLL side loading, and a fresh instance of the signed build tool MSBuild.exe runs a SectopRAT or ArechClient2 remote access trojan entirely in memory. Persistence is established by copying ZigCryptoStealer into a randomly named folder and pointing a matching autorun registry value at it, so it relaunches on every logon. One of the payloads resolves its command and control configuration through EtherHiding, reading a public blockchain smart contract instead of a domain, which survives takedowns since updates only require a low cost transaction rather than new infrastructure.

To decrypt the browser's own stored passwords and cookies, a fresh instance of MSBuild.exe launches the victim's real Chrome or Edge browser against a disposable profile with sandboxing disabled, and the intrusion then reads those secrets straight from the profile on disk. Stolen data is exfiltrated over the same connection Vidar already uses for command and control, and rundll32.exe resolves that same C2 domain through DNS over HTTPS instead of a normal DNS lookup.

The delivery infrastructure sits behind Cloudflare and reuses a small set of TLS certificates across dozens of ordinary looking apex domains, each with its own randomly named subdomain serving the payload. Pivoting from one delivery domain through shared certificate and certificate transparency data surfaced the full cluster, confirming that every apex domain's own name is also reused as a subdomain label under a single attacker owned zone, fg777-srv[.]top, and that targeting is opportunistic rather than sector specific.

DOMAIN 119
fg777-srv.top
patxisdublin.com
jetourmexico.com
lunabybodyshaping.com
dbqu.highkickstkd.com
uumt.opulentbeautybarllc.com
zvuy.comptonanimalrescue.com
ljxh.patxisdublin.com
bikertlane.com
bittersweetkennel.com
bolesfarms.com
borrender.com
burritodelight.com
cardanaircraft.org
cheaperthan-dirt.com
cleantruckchecksac.com
closedfistllc.com
colg1.org
comptonanimalrescue.com
concretewestgj.com
corgiwarehouse.com
customhomebuildersplainfield.com
dermatologycongress.org
dermexcel.net
diamonddumpsterrental.net
divanailsachse.com
domirunway.com
economywindowsparts.com
everestpointnorthglenn.org
ezgarageautorepairtx.com
nurtured-in-nature.com
finovestpedia.com
fit2leadconference.com
fontanayoga.com
frisbeeburgerllc.com
gobgem.com
goodlifelakerentals.com
hairbyniki.com
hayleymarienorman.com
highkickstkd.com
hurtigegevinster.com
jenslittlerugrats.org
kaltourusa.com
letstalkrocks.com
lnlsealcoating.com
loganlooneyresume.com
mechanic-on-site.com
missavws.net
monicarobles.org
opulentbeautybarllc.com
ordereltacofeliz.com
pacesettershomehealth.com
polarstartire.com
ricardotaxiservices.com
ridgerenovation.com
riggsjacksboro.com
rspmpanyabungan.com
scissormasterstanningsalon.com
sdcwoodcraft.com
seamsnstitches.com
shawnmaltipoopuppies.com
shopsoleilcollective.com
slepsluzbaublizini.com
snydersflowershop.com
solucionesintegralesgiraldo.com
spacedecorideas.com
spencershorttexas.com
springhillcommons.com
stable-virtual-camera.com
studiofourfitnessnv.com
taqueriadonamariaky.com
thebrandus.com
thechildrencomefirst.org
thelegalexpertise.com
thetokestudio.com
trueamatuermodels.com
upthesmokee.com
vitalmcallen.com
wellcome-c-store.com
whitelaneint.com
windhorseevents.com
aimhighbasketballcamp.com
alliancecarerx.com
apk.yumaneed.com
ashleynewsome.com
atwaternaz.com
auraapp.org
bbibeautyshop.com
bedfordrealtycorp.com
bibisafricanhairbraids.com
breezybowlhouston.com
breezybowlstlouis.com
dcsplumb.com
design.yumaneed.com
enjoyflowersbusiness.com
glendoradentalcenter.com
human.yumaneed.com
infinitymakeoverstudio.com
internationaltreeservice.com
matecfilterpress.com
mcbridervpark.com
mobile.breezybowlhouston.com
mobile.yumaneed.com
modelstvseries.com
project.yumaneed.com
protransportationservice.com
rohamsport.com
rsudtarutung.com
seattle-immigrationlawyer.com
store.ridgerenovation.com
story.yumaneed.com
taxi88.ashleynewsome.com
thehairspotsalon.com
tmowersnstuff.com
wss.vectorplatform.cc
quorashift.cc
static.quorashift.cc
gw.portallbridge.cc
xss.gumminessheap.in.net
IP ADDRESS 1
45.140.14.113
SHA256 FILE HASH 3
40bc68612f43cdf66737784640a706efdbdad24c0423d5e08ef47cc6ebd97ffc
99279a25c028fc85747e68521fc5dee135bcfa01602fd3109cba81959db476d4
17d4935ddc1f05cc18861b8270d935d52fa77bda00ca3e694cdedd807a8e0d78

Detections (10)

Enable detections →

Connect your environment for suggestions and queries personalized to your security telemetry.

  • Pcalua Proxy Execution Of Script Interpreter
  • PowerShell Command Line Constructing a Hidden WMI Process Creation Call
  • Rundll32 Ordinal Execution of a Non DLL Named File
  • ClickFix Explorer Spawning Command Execution Proxy Binary
  • MSBuild.exe Launched With No Command Line by an Untrusted Parent Process
  • Non-Browser Process Connecting to Ethereum RPC
  • Known Sideloading Target Library Loaded From a User Writable Directory
  • Trace or ETW Logging Disabled by a .NET Process
  • Non-Browser Process Launching a Real Browser with Sandboxing Disabled and a Disposable Profile