
About this episode
Today we are joined by Ben Folland, Security Operations Analyst from Huntress, discussing their work on "ClickFix Gets Creative: Malware Buried in Images." This analysis covers a ClickFix campaign that uses fake human verification checks and a realistic Windows Update screen to trick users into manually running malicious commands.
The multi-stage attack chain leverages mshta.exe, PowerShell, and .NET loaders, ultimately delivering infostealers like LummaC2 and Rhadamanthys, with payloads hidden inside PNG images using steganography. While technically sophisticated, the campaign hinges on simple user interaction, underscoring the importance of user awareness and controls around command execution.
The research can be found here:
ClickFix Gets Creative: Malware Buried in Images
Get every episode summarized
Each time CyberWire Daily publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from CyberWire Daily

Clear your calendar, it’s Patch Tuesday.
CyberWire Daily
Sep 9, 202630:40completed

Worming its way through WeChat.
CyberWire Daily
Sep 8, 202630:03completed

This call may be monitored. [Special Edition]
CyberWire Daily
Sep 7, 202638:33pending

When hackers control the clock. [T-Minus: Space-Cyber Briefing]
CyberWire Daily
Sep 6, 202623:43pending