216.73.217.22

User interaction with a ClickFix-style phishing site resulted in execution of an obfuscated PowerShell command

· Published 29/04/2026 10:33 · Modified 29/04/2026 11:14

Export JSON

Essential information

Published
29/04/2026 10:33
Modified
29/04/2026 11:14
Tags
2026-04-29 clickfix credential-theft dll sideloading hijackloader information stealer lumma stealer lummastealer phishing powershell
Related entities
6 observables, 15 techniques (mitre), 3 malware, 1 others

Description

A -style campaign leveraged social engineering to trick users into executing obfuscated commands that downloaded and installed a malicious MSI payload from a remote server. The attack employed a sophisticated multi-stage infection chain utilizing techniques with renamed legitimate binaries to execute malicious components. The final payload deployed to deliver a Lumma-style designed for credential harvesting and data exfiltration. The campaign utilized multiple command-and-control domains and infrastructure hosted on specific IP addresses. Mitigation measures include blocking identified artifacts, enhancing user awareness about social engineering tactics, implementing endpoint detection for suspicious activity and unsigned , and isolating compromised systems for remediation.

External references