Investigating a new Click-fix variant

March 16, 2026, 10:52 a.m.

Description

A new variant of the ClickFix technique has been identified, where attackers convince users to execute malicious commands on their devices through the Win + R shortcut. This variation uses a 'net use' command to map a network drive from an external server, followed by executing a '.cmd' batch file. The script downloads a ZIP archive, unpacks it, and executes a legitimate WorkFlowy application with modified, malicious logic hidden inside an '.asar' archive. This acts as a C2 beacon and a dropper for the final malware payload. The attack bypasses typical detection methods and utilizes Electron application bundling to hide malicious code.

Date

  • Created: March 16, 2026, 10:28 a.m.
  • Published: March 16, 2026, 10:28 a.m.
  • Modified: March 16, 2026, 10:52 a.m.

Indicators

  • dc95f7c7fb98ec30d3cb03963865a11d1b7b696e34f163b8de45f828b62ec829
  • 9ee58eb59e337c06429ff3f0afd0ee6886b0644ddd4531305b269e97ad2b8d42
  • a390fe045f50a0697b14160132dfa124c7f92d85c18fba07df351c2fcfc11063
  • 144.31.165.173
  • https://cloudflare.report/forever/e/
  • http://cloudflare.report/forever/e/

Attack Patterns

Additional Informations

  • cloudflare.report
  • happyglamper.ro