Date: 08/13/2026
Severity: High
Summary
ClickFix campaign that used compromised WordPress websites and Cloudflare-themed social engineering lures to trick users into executing a malicious PowerShell command. The attack abused the legitimate Deno JavaScript runtime and winget to install Deno, execute remote JavaScript, and deliver a Python-based infostealer through an MSI staging chain. The malware also established persistence via Registry Run keys, performed system reconnaissance, and demonstrated fileless execution techniques to evade traditional endpoint detection.
Indicators of Compromise (IOC) List
Domain/URLs | columbnezhjdq.com webstizkgao.com ordinary-computer-analytical-spell.trycloudflare.com |
IP Address | 162.33.177.16 |
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "columbnezhjdq.com" or url like "columbnezhjdq.com" or siteurl like "columbnezhjdq.com" or domainname like "ordinary-computer-analytical-spell.trycloudflare.com" or url like "ordinary-computer-analytical-spell.trycloudflare.com" or siteurl like "ordinary-computer-analytical-spell.trycloudflare.com" or domainname like "webstizkgao.com" or url like "webstizkgao.com" or siteurl like "webstizkgao.com" |
Detection Query 2 : | dstipaddress IN ("162.33.177.16") or srcipaddress IN ("162.33.177.16") |
Reference:
https://www.sophos.com/en-us/blog/clickfix-campaign-abuses-deno-runtime-for-infostealer-delivery