PULSE NAME
Analyzing a Full ClickFix Attack Chain - Part 1
WHITE AlienVault 2026-04-23 Modified: 2026-04-23
7
IOCs
LOW VOLUME
A sophisticated ClickFix campaign was detected in mid-March 2026, beginning with a malicious webpage impersonating Booking.com's visual identity with a fake CAPTCHA. The attack leverages social engineering to trick victims into executing a PowerShell command that downloads and runs a script directly in memory. The JavaScript code automatically copies malicious commands to the clipboard and intercepts copy events. Once executed, the PowerShell dropper performs system fingerprinting, downloads a ZIP payload from a remote server, deploys it to user directories, establishes persistence through registry keys and scheduled tasks, and executes the final payload. The campaign demonstrates well-structured code with fallback mechanisms and real-time telemetry via Telegram, suggesting the use of a ready-to-use attack kit.
Indicators of Compromise (7)
All URL domain
TYPEINDICATORDESCRIPTIONCREATED
URL https://hailmeinc.com/bkmsiqop.zip 2026-04-23
URL https://hailmeinc.com/bkmsiqop.zip' 2026-04-23
URL https://wiosyrondaty.com 2026-04-23
domain accountpulsecentre.help 2026-04-23
domain hailmeinc.com 2026-04-23
domain textarea.select 2026-04-23
domain wiosyrondaty.com 2026-04-23