PULSE NAME
Fake Windows Update Screens Used by ClickFix to Deliver Steganographic Malware
WHITE cryptocti 2025-11-25 Modified: 2025-12-25
42
IOCs
MEDIUM VOLUME
New wave of clickFix attacks is identified to abuse highly realistic fake Windows Update screens and PNG image steganography to secretly deploy info stealing malware.
Indicators of Compromise (42)
All URL domain
TYPEINDICATORDESCRIPTIONCREATED
URL http://securitysettings.live 2025-11-25
URL http://xoiiasdpsdoasdpojas.com 2025-11-25
URL http://141.98.80.175/ercx.dat 2025-11-25
URL http://141.98.80.175/gpsc.dat 2025-11-25
URL http://141.98.80.175/rtdx.dat 2025-11-25
URL http://141.98.80.175/tick.odd 2025-11-25
URL http://141.98.80.175/very.dat 2025-11-25
URL http://81.90.29.64/ebc/rps.gz 2025-11-25
URL http://94.74.164.136/fifx.odd 2025-11-25
URL http://bendavo.su/asdsa 2025-11-25
URL http://conxmsw.su/vcsf 2025-11-25
URL http://corezea.com/ebc 2025-11-25
URL http://exposqw.su/casc 2025-11-25
URL http://narroxp.su/rewd 2025-11-25
URL http://ozonelf.su/asd 2025-11-25
URL http://squatje.su/asdasd 2025-11-25
URL http://squeaue.su/qwe 2025-11-25
URL http://vicareu.su/bcdf 2025-11-25
URL https://cybersecuritynews.co 2025-11-25
domain bendavo.su 2025-11-25
domain cmevents.live 2025-11-25
domain cmevents.pro 2025-11-25
domain conxmsw.su 2025-11-25
domain corezea.com 2025-11-25
domain cosmicpharma-bd.com 2025-11-25
domain cybersecuritynews.co 2025-11-25
domain exposqw.su 2025-11-25
domain galaxyswapper.pro 2025-11-25
domain groupewadesecurity.com 2025-11-25
domain hypudyk.shop 2025-11-25
domain narroxp.su 2025-11-25
domain ozonelf.su 2025-11-25
domain securitysettings.live 2025-11-25
domain sportsstories.gr 2025-11-25
domain squatje.su 2025-11-25
domain squeaue.su 2025-11-25
domain vicareu.su 2025-11-25
domain virhtechgmbh.com 2025-11-25
domain xcvcxoipoeww.site 2025-11-25
domain xmcniiadpwqw.site 2025-11-25
domain xoiiasdpsdoasdpojas.com 2025-11-25
domain xpoalswwkjddsljsy.com 2025-11-25