← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
ClickFix Removes Your Background but Leaves the Malware
BackgroundFix masquerades as a free image-editing tool but functions as a ClickFix social engineering lure. The fake service prompts users to verify they are human, copying malicious commands to their clipboard that invoke finger.exe to retrieve additional payloads. This chain delivers CastleLoader, which subsequently drops NetSupport RAT and a custom .NET stealer dubbed CastleStealer. The loader uses reflective PE injection, API hashing, and ChaCha20-encrypted C2 communications. CastleStealer targets browser credentials, cryptocurrency wallet extensions, and Telegram sessions through DPAPI decryption and Restart Manager APIs. The campaign leverages BYOI tactics with embedded Python interpreters and multiple shellcode stages. A notable implementation flaw exists where launch method 4 references regsrv32.exe instead of the correct regsvr32.exe, causing silent failures.
MITRE ATT&CK & Malware Families
Indicators of Compromise (3 / 22 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA256 | bde21d8be65d31e1c380f2daae2f73c79f3e1f4bca70fb990db6fdf6c3768c92 | — | 2026-04-30 | |
| FileHash-SHA256 | ed391a16389234f9ebb6727711baaf3e068d7f77c465708fa3e8b7d0565d7fb9 | — | 2026-04-30 | |
| FileHash-SHA256 | f5dbaa09e60343f252a80d4a313a36ac11442d96b0896022d1a83744e3c11feb | — | 2026-04-30 |