Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators User interaction with a ClickFix-style phishing site resulted in execution of an obfuscated PowerShell command

85.11.161.198

TLP:CLEAR
Active

IPv4 Address

Description

A ClickFix-style phishing campaign leveraged social engineering to trick users into executing obfuscated PowerShell commands that downloaded and installed a malicious MSI payload from a remote server. The attack employed a sophisticated multi-stage infection chain utilizing DLL sideloading techniques with renamed legitimate binaries to execute malicious components. The final payload deployed HijackLoader to deliver a Lumma-style information stealer designed for credential harvesting and data exfiltration. The campaign utilized multiple command-and-control domains and infrastructure hosted on specific IP addresses. Mitigation measures include blocking identified artifacts, enhancing user awareness about ClickFix social engineering tactics, implementing endpoint detection for suspicious PowerShell activity and unsigned DLL sideloading, and isolating compromised systems for remediation.

Sightings (0)

No sightings recorded yet

Details

Name / Label
User interaction with a ClickFix-style phishing site resulted in execution of an obfuscated PowerShell command
Pattern Type
STIX
Confidence
75%
Valid From
May 3, 2026 16:06
Total Sightings
0
Added
May 3, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 85.11.161.198

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.