PULSE NAME
ClickFix Removes Your Background but Leaves the Malware
WHITE ClickFix AlienVault 2026-04-30 Modified: 2026-05-30
22
IOCs
MEDIUM VOLUME
BackgroundFix masquerades as a free image-editing tool but functions as a ClickFix social engineering lure. The fake service prompts users to verify they are human, copying malicious commands to their clipboard that invoke finger.exe to retrieve additional payloads. This chain delivers CastleLoader, which subsequently drops NetSupport RAT and a custom .NET stealer dubbed CastleStealer. The loader uses reflective PE injection, API hashing, and ChaCha20-encrypted C2 communications. CastleStealer targets browser credentials, cryptocurrency wallet extensions, and Telegram sessions through DPAPI decryption and Restart Manager APIs. The campaign leverages BYOI tactics with embedded Python interpreters and multiple shellcode stages. A notable implementation flaw exists where launch method 4 references regsrv32.exe instead of the correct regsvr32.exe, causing silent failures.
Indicators of Compromise (14 / 22 total)
All FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
domain ai-scan.digital 2026-04-30
domain background-off.com 2026-04-30
domain background-ready.online 2026-04-30
domain backgroundformat.online 2026-04-30
domain bg-go.online 2026-04-30
domain bg-ready.online 2026-04-30
domain bg-removerok.online 2026-04-30
domain bg-transparency.online 2026-04-30
domain brionter.com 2026-04-30
domain cheeshomireciple.com 2026-04-30
domain giovettiadv.com 2026-04-30
domain obelnamevalf.org 2026-04-30
domain poronto.com 2026-04-30
domain trindastal.com 2026-04-30