A ClickFix cluster: Observed activity from recent ClickFix campaigns

    Date: 08/31/2026

    Severity: High

    Summary

    A recent ClickFix campaign cluster used three different infection approaches to gain initial access, combining DLL sideloading, consistent file-naming patterns, and C2 dead drops. Attackers also used aggressive phone-based social engineering, directing victims to compromised WordPress websites hosting ClickFix lures. The activity demonstrates how threat actors continue to evolve ClickFix delivery methods to establish footholds in victim environments. 

    Indicators of Compromise (IOC) List 

    Domains/URLs

    seephotoalbum.com

    beastcloudsecurity.com

    bestpopularimages.com

    photocategories.com

    topimagechecker.com

    editdocumentfree.com

    newpopularimages.com

    topphotoalbum.com

    opendocumentonline.com

    peekyourphoto.com

    digitalpoint.com/members/trytodetectme.1134520

    digitalpoint.com/members/documentpublisher.1139897

    IP Address

    144.172.103.194

    146.19.49.4

    149.56.95.157

    91.236.230.237

    130.49.155.201

    146.19.49.71

    145.239.54.189

    193.243.147.137

    45.83.180.237

    45.129.199.77

    Hash

    72cd20b5a398febd6868e1b88e86afb5a8163969b8cd7bb7895f52fc9ea4424d

    7545d737202df6d90118e04a963acbd1b16a1f4e0a1c173bef7ab9489efdcd16

    2104e7018aa9fd2507cc036e2aa4ff80e613a156ab1cb78604773d447298a854

    f80d8f5950086a053c68dcdcb5902f2ad8b8e4fcf400855c316aef09fe0f55e5 

    6304d348b45154b4d6d7c3f1176304d2c0112d23c08a0178fa6d0b74a967a85d 

    32b1f676dd98449a47ba671c4bdd6269e070a8fb349d1c02404a3784b4d4c77f 

    d092ac012ccb75416802ee697a5f65b2c0545d047a20869c53124db9e37f3dcd 

    4cbaac416954408f37ebcc97ba4c08facef86c20b3cbec9324a4932b5fc1acbb 

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "newpopularimages.com" or url like "newpopularimages.com" or siteurl like "newpopularimages.com" or domainname like "editdocumentfree.com" or url like "editdocumentfree.com" or siteurl like "editdocumentfree.com" or domainname like "beastcloudsecurity.com" or url like "beastcloudsecurity.com" or siteurl like "beastcloudsecurity.com" or domainname like "bestpopularimages.com" or url like "bestpopularimages.com" or siteurl like "bestpopularimages.com" or domainname like "topimagechecker.com" or url like "topimagechecker.com" or siteurl like "topimagechecker.com" or domainname like "photocategories.com" or url like "photocategories.com" or siteurl like "photocategories.com" or domainname like "peekyourphoto.com" or url like "peekyourphoto.com" or siteurl like "peekyourphoto.com" or domainname like "opendocumentonline.com" or url like "opendocumentonline.com" or siteurl like "opendocumentonline.com" or domainname like "topphotoalbum.com" or url like "topphotoalbum.com" or siteurl like "topphotoalbum.com" or domainname like "seephotoalbum.com" or url like "seephotoalbum.com" or siteurl like "seephotoalbum.com" or domainname like "digitalpoint.com/members/trytodetectme.1134520" or siteurl like "digitalpoint.com/members/trytodetectme.1134520" or url like "digitalpoint.com/members/trytodetectme.1134520" or domainname like "digitalpoint.com/members/documentpublisher.1139897" or siteurl like "digitalpoint.com/members/documentpublisher.1139897" or url like "digitalpoint.com/members/documentpublisher.1139897"

    Detection Query 2 :

    dstipaddress IN ("45.129.199.77","149.56.95.157","130.49.155.201","145.239.54.189","193.243.147.137","45.83.180.237","144.172.103.194","146.19.49.71","146.19.49.4","91.236.230.237") or srcipaddress IN ("45.129.199.77","149.56.95.157","130.49.155.201","145.239.54.189","193.243.147.137","45.83.180.237","144.172.103.194","146.19.49.71","146.19.49.4","91.236.230.237")

    Detection Query 3 :

    sha256hash IN ("72cd20b5a398febd6868e1b88e86afb5a8163969b8cd7bb7895f52fc9ea4424d","7545d737202df6d90118e04a963acbd1b16a1f4e0a1c173bef7ab9489efdcd16","2104e7018aa9fd2507cc036e2aa4ff80e613a156ab1cb78604773d447298a854","f80d8f5950086a053c68dcdcb5902f2ad8b8e4fcf400855c316aef09fe0f55e5","6304d348b45154b4d6d7c3f1176304d2c0112d23c08a0178fa6d0b74a967a85d","32b1f676dd98449a47ba671c4bdd6269e070a8fb349d1c02404a3784b4d4c77f","d092ac012ccb75416802ee697a5f65b2c0545d047a20869c53124db9e37f3dcd","4cbaac416954408f37ebcc97ba4c08facef86c20b3cbec9324a4932b5fc1acbb")

    Reference:    

    https://fieldeffect.com/blog/clickfix-cluster-observed-activity-recent-campaigns#61az5k                                         


    Tags

    MalwareClickFixDLLSideLoadingSocial EngineeringWordPress

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags