Date: 08/06/2026
Severity: High
Summary
A newly observed ClickFix variant abuses the legitimate Windows binary pcalua.exe to evade parent-process detection and launch malicious activity. Victims are tricked into executing a crafted command that initiates PowerShell, spawns cmd.exe via WMI, and mounts a remote WebDAV share. The malware is delivered through CDN-backed HTTPS infrastructure using unique tokenized URLs and executed with rundll32.exe. Once loaded, the malicious DLL deploys infostealer functionality on the compromised host. Researchers also identified the same infrastructure serving payloads under alternate filenames such as gz.keu and bn.js, suggesting multiple concurrent malware distribution campaigns operated by the same threat actor.
Indicators of Compromise (IOC) List
Domains/URLs | hvao.jbgroup21.com sutf.kafekarachi.com cglp.cleantruckchecksac.com Igsx.closedfistllc.com hmvc.ridgerenovation.com dgctf.concretewestgj.com vertexengine.cc vectorplatform.cc https://hvao.jbgroup21.com/60861fb4-c42e-4d32-9d1e-7f445fbb4fbe https://sutf.kafekarachi.com/9f2d1350-68ae-425a-8161-cb99132f828d https://cglp.cleantruckchecksac.com/675b759f-393e-4c37-9d92-92f3098f145e https://igsx.closedfistllc.com/127c3bcd-412d-442c-bb65-395afc1c8977 https://dgctf.concretewestgj.com/7e06668f-b098-4430-afb9-0b5ba2c561f8 https://hmvc.ridgerenovation.com/3dc45b30-111c-49fa-9657-9e53d4e089ae |
Hash | 13a41f154e00a331049db462866533fcfe238e98ce6bcf2b6ed18cd96d0d1222 68dda950df8971a2beef3f308a00d6c0ed9cc1873922a94930f5177867282b9f |
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "vectorplatform.cc" or url like "vectorplatform.cc" or siteurl like "vectorplatform.cc" or domainname like "cglp.cleantruckchecksac.com" or url like "cglp.cleantruckchecksac.com" or siteurl like "cglp.cleantruckchecksac.com" or domainname like "https://hmvc.ridgerenovation.com/3dc45b30-111c-49fa-9657-9e53d4e089ae" or url like "https://hmvc.ridgerenovation.com/3dc45b30-111c-49fa-9657-9e53d4e089ae" or siteurl like "https://hmvc.ridgerenovation.com/3dc45b30-111c-49fa-9657-9e53d4e089ae" or domainname like "sutf.kafekarachi.com" or url like "sutf.kafekarachi.com" or siteurl like "sutf.kafekarachi.com" or domainname like "https://igsx.closedfistllc.com/127c3bcd-412d-442c-bb65-395afc1c8977" or url like "https://igsx.closedfistllc.com/127c3bcd-412d-442c-bb65-395afc1c8977" or siteurl like "https://igsx.closedfistllc.com/127c3bcd-412d-442c-bb65-395afc1c8977" or domainname like "hvao.jbgroup21.com" or url like "hvao.jbgroup21.com" or siteurl like "hvao.jbgroup21.com" or domainname like "dgctf.concretewestgj.com" or url like "dgctf.concretewestgj.com" or siteurl like "dgctf.concretewestgj.com" or domainname like "hmvc.ridgerenovation.com" or url like "hmvc.ridgerenovation.com" or siteurl like "hmvc.ridgerenovation.com" or domainname like "https://cglp.cleantruckchecksac.com/675b759f-393e-4c37-9d92-92f3098f145e" or url like "https://cglp.cleantruckchecksac.com/675b759f-393e-4c37-9d92-92f3098f145e" or siteurl like "https://cglp.cleantruckchecksac.com/675b759f-393e-4c37-9d92-92f3098f145e" or domainname like "https://hvao.jbgroup21.com/60861fb4-c42e-4d32-9d1e-7f445fbb4fbe" or url like "https://hvao.jbgroup21.com/60861fb4-c42e-4d32-9d1e-7f445fbb4fbe" or siteurl like "https://hvao.jbgroup21.com/60861fb4-c42e-4d32-9d1e-7f445fbb4fbe" or domainname like "Igsx.closedfistllc.com" or url like "Igsx.closedfistllc.com" or siteurl like "Igsx.closedfistllc.com" or domainname like "hmvc.ridgerenovation.com" or url like "hmvc.ridgerenovation.com" or siteurl like "hmvc.ridgerenovation.com" or domainname like "vertexengine.cc" or url like "vertexengine.cc" or siteurl like "vertexengine.cc" or domainname like "https://sutf.kafekarachi.com/9f2d1350-68ae-425a-8161-cb99132f828d" or url like "https://sutf.kafekarachi.com/9f2d1350-68ae-425a-8161-cb99132f828d" or siteurl like "https://sutf.kafekarachi.com/9f2d1350-68ae-425a-8161-cb99132f828d" or domainname like "https://dgctf.concretewestgj.com/7e06668f-b098-4430-afb9-0b5ba2c561f8" or url like "https://dgctf.concretewestgj.com/7e06668f-b098-4430-afb9-0b5ba2c561f8" or siteurl like "https://dgctf.concretewestgj.com/7e06668f-b098-4430-afb9-0b5ba2c561f8" |
Detection Query 2 : | sha256hash IN ("13a41f154e00a331049db462866533fcfe238e98ce6bcf2b6ed18cd96d0d1222","68dda950df8971a2beef3f308a00d6c0ed9cc1873922a94930f5177867282b9f")
|
Reference:
https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2026-08-05-New-Clickfix-Variant.txt