Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators What Is the BabaDeda Loader? Analysis of a New ClickFix Malware Campaign.

http://95.163.152.190/linguist.zip

TLP:CLEAR
Active

URL

Description

The BabaDeda loader family has undergone significant advancements in its capabilities, particularly in stealth, evasion, and payload flexibility. Discovered during April 2026, this evolved framework continues to conceal malicious payloads within seemingly legitimate installer packages while expanding its functionality. The attack methodology begins with a social engineering exploit known as ClickFix, which encourages users to execute commands via trusted operating system utilities. This initial step transitions into a sophisticated multi-stage loader that employs several tactics, including hidden PowerShell commands, in-memory shellcode, DLL sideloading, and external payload storage.

Sightings (0)

No sightings recorded yet

Details

Name / Label
What Is the BabaDeda Loader? Analysis of a New ClickFix Malware Campaign.
Pattern Type
STIX
Confidence
75%
Valid From
Jul 12, 2026 03:08
Total Sightings
0
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of http://95.163.152.190/linguist.zip

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.