New ClickFix Variant Abuses the Legitimate Binary and WebDAV to Deploy Infostealer Capabilities

    Date: 08/06/2026

    Severity: High

    Summary

    A newly observed ClickFix variant abuses the legitimate Windows binary pcalua.exe to evade parent-process detection and launch malicious activity. Victims are tricked into executing a crafted command that initiates PowerShell, spawns cmd.exe via WMI, and mounts a remote WebDAV share. The malware is delivered through CDN-backed HTTPS infrastructure using unique tokenized URLs and executed with rundll32.exe. Once loaded, the malicious DLL deploys infostealer functionality on the compromised host. Researchers also identified the same infrastructure serving payloads under alternate filenames such as gz.keu and bn.js, suggesting multiple concurrent malware distribution campaigns operated by the same threat actor.

    Indicators of Compromise (IOC) List

    Domains/URLs

    hvao.jbgroup21.com

    sutf.kafekarachi.com

    cglp.cleantruckchecksac.com

    Igsx.closedfistllc.com

    hmvc.ridgerenovation.com 

    dgctf.concretewestgj.com

    vertexengine.cc

    vectorplatform.cc

    https://hvao.jbgroup21.com/60861fb4-c42e-4d32-9d1e-7f445fbb4fbe

    https://sutf.kafekarachi.com/9f2d1350-68ae-425a-8161-cb99132f828d

    https://cglp.cleantruckchecksac.com/675b759f-393e-4c37-9d92-92f3098f145e

    https://igsx.closedfistllc.com/127c3bcd-412d-442c-bb65-395afc1c8977

    https://dgctf.concretewestgj.com/7e06668f-b098-4430-afb9-0b5ba2c561f8 

    https://hmvc.ridgerenovation.com/3dc45b30-111c-49fa-9657-9e53d4e089ae

    Hash  

    13a41f154e00a331049db462866533fcfe238e98ce6bcf2b6ed18cd96d0d1222

    68dda950df8971a2beef3f308a00d6c0ed9cc1873922a94930f5177867282b9f

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "vectorplatform.cc" or url like "vectorplatform.cc" or siteurl like "vectorplatform.cc" or domainname like "cglp.cleantruckchecksac.com" or url like "cglp.cleantruckchecksac.com" or siteurl like "cglp.cleantruckchecksac.com" or domainname like "https://hmvc.ridgerenovation.com/3dc45b30-111c-49fa-9657-9e53d4e089ae" or url like "https://hmvc.ridgerenovation.com/3dc45b30-111c-49fa-9657-9e53d4e089ae" or siteurl like "https://hmvc.ridgerenovation.com/3dc45b30-111c-49fa-9657-9e53d4e089ae" or domainname like "sutf.kafekarachi.com" or url like "sutf.kafekarachi.com" or siteurl like "sutf.kafekarachi.com" or domainname like "https://igsx.closedfistllc.com/127c3bcd-412d-442c-bb65-395afc1c8977" or url like "https://igsx.closedfistllc.com/127c3bcd-412d-442c-bb65-395afc1c8977" or siteurl like "https://igsx.closedfistllc.com/127c3bcd-412d-442c-bb65-395afc1c8977" or domainname like "hvao.jbgroup21.com" or url like "hvao.jbgroup21.com" or siteurl like "hvao.jbgroup21.com" or domainname like "dgctf.concretewestgj.com" or url like "dgctf.concretewestgj.com" or siteurl like "dgctf.concretewestgj.com" or domainname like "hmvc.ridgerenovation.com" or url like "hmvc.ridgerenovation.com" or siteurl like "hmvc.ridgerenovation.com" or domainname like "https://cglp.cleantruckchecksac.com/675b759f-393e-4c37-9d92-92f3098f145e" or url like "https://cglp.cleantruckchecksac.com/675b759f-393e-4c37-9d92-92f3098f145e" or siteurl like "https://cglp.cleantruckchecksac.com/675b759f-393e-4c37-9d92-92f3098f145e" or domainname like "https://hvao.jbgroup21.com/60861fb4-c42e-4d32-9d1e-7f445fbb4fbe" or url like "https://hvao.jbgroup21.com/60861fb4-c42e-4d32-9d1e-7f445fbb4fbe" or siteurl like "https://hvao.jbgroup21.com/60861fb4-c42e-4d32-9d1e-7f445fbb4fbe" or domainname like "Igsx.closedfistllc.com" or url like "Igsx.closedfistllc.com" or siteurl like "Igsx.closedfistllc.com" or domainname like "hmvc.ridgerenovation.com" or url like "hmvc.ridgerenovation.com" or siteurl like "hmvc.ridgerenovation.com" or domainname like "vertexengine.cc" or url like "vertexengine.cc" or siteurl like "vertexengine.cc" or domainname like "https://sutf.kafekarachi.com/9f2d1350-68ae-425a-8161-cb99132f828d" or url like "https://sutf.kafekarachi.com/9f2d1350-68ae-425a-8161-cb99132f828d" or siteurl like "https://sutf.kafekarachi.com/9f2d1350-68ae-425a-8161-cb99132f828d" or domainname like "https://dgctf.concretewestgj.com/7e06668f-b098-4430-afb9-0b5ba2c561f8" or url like "https://dgctf.concretewestgj.com/7e06668f-b098-4430-afb9-0b5ba2c561f8" or siteurl like "https://dgctf.concretewestgj.com/7e06668f-b098-4430-afb9-0b5ba2c561f8" 

    Detection Query 2 :

    sha256hash IN ("13a41f154e00a331049db462866533fcfe238e98ce6bcf2b6ed18cd96d0d1222","68dda950df8971a2beef3f308a00d6c0ed9cc1873922a94930f5177867282b9f")

    Reference:    

    https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2026-08-05-New-Clickfix-Variant.txt    


    Tags

    MalwareClickFixInfostealer

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags