Regional News Site Delivers Stealc via ClickFix

    Date: 09/15/2026

    Severity: High

    Summary

    A compromised regional news outlet injected malicious JavaScript that triggers a ClickFix prompt, using a cookie check to control execution. The lure tricks users into running an obfuscated CMD/PowerShell command, which downloads and executes an encrypted, compressed payload. The payload is reflectively loaded in memory and ultimately delivers Stealc InfoStealer, enabling credential/session-token theft through browser-focused process injection.

    Indicators of Compromise (IOC) List 

    Domain/URLs

    chunks.cdnsuicaches.com

    Mnl.ac

    IP Address

    45.74.7.27

    23.227.198.199

    Hash

    1e4246ed2050b7a6c711aae4732e8ec89d590dec860d16ecc86071339792135f

    41da18c32a2c759946acd9e2291e937b0777e19db6407126807f9af52374e3c0

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "Mnl.ac" or url like "Mnl.ac" or siteurl like "Mnl.ac" or domainname like "chunks.cdnsuicaches.com" or url like "chunks.cdnsuicaches.com" or siteurl like "chunks.cdnsuicaches.com"

    Detection Query 2 :

    dstipaddress IN ("45.74.7.27","23.227.198.199") or srcipaddress IN ("45.74.7.27","23.227.198.199")

    Detection Query 3 :

    sha256hash IN ("41da18c32a2c759946acd9e2291e937b0777e19db6407126807f9af52374e3c0","1e4246ed2050b7a6c711aae4732e8ec89d590dec860d16ecc86071339792135f")

    Reference: 

    https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2026-09-14-Regional-News-Outlet-Infected-With-Malicious-JavaScript.txt     


    Tags

    MalwareClickFixObfuscationCredential HarvestingPowerShell AttackInfostealerSTEALC

    « Previous Article

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags