PULSE NAME
ClickFix Removes Your Background but Leaves the Malware
WHITE ClickFix AlienVault 2026-04-30 Modified: 2026-05-30
22
IOCs
MEDIUM VOLUME
BackgroundFix masquerades as a free image-editing tool but functions as a ClickFix social engineering lure. The fake service prompts users to verify they are human, copying malicious commands to their clipboard that invoke finger.exe to retrieve additional payloads. This chain delivers CastleLoader, which subsequently drops NetSupport RAT and a custom .NET stealer dubbed CastleStealer. The loader uses reflective PE injection, API hashing, and ChaCha20-encrypted C2 communications. CastleStealer targets browser credentials, cryptocurrency wallet extensions, and Telegram sessions through DPAPI decryption and Restart Manager APIs. The campaign leverages BYOI tactics with embedded Python interpreters and multiple shellcode stages. A notable implementation flaw exists where launch method 4 references regsrv32.exe instead of the correct regsvr32.exe, causing silent failures.
Indicators of Compromise (3 / 22 total)
All FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 bde21d8be65d31e1c380f2daae2f73c79f3e1f4bca70fb990db6fdf6c3768c92 2026-04-30
FileHash-SHA256 ed391a16389234f9ebb6727711baaf3e068d7f77c465708fa3e8b7d0565d7fb9 2026-04-30
FileHash-SHA256 f5dbaa09e60343f252a80d4a313a36ac11442d96b0896022d1a83744e3c11feb 2026-04-30