Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
ClickFix Campaigns Enhance Malware Tactics with New Loaders

ClickFix Campaigns Enhance Malware Tactics with New Loaders

Posted on June 16, 2026 By CWS

Recent reports from cybersecurity firms Morphisec, BlueVoyant, and Huntress highlight advanced ClickFix campaigns deploying three new malware loaders: BabaDeda Loader, Lorem Ipsum Loader, and Potemkin. These campaigns are notable for their sophisticated methods of distribution and payload delivery.

Enhanced Malware Techniques with BabaDeda Loader

In April 2026, BabaDeda Loader attacks surfaced, targeting sectors such as education and finance. Initially discovered by Morphisec, BabaDeda Loader has evolved from hiding malicious content in legitimate installer packages to employing stealthier and more flexible delivery mechanisms. Attacks start with ClickFix social engineering attempts that trick victims into running PowerShell commands. The loader subsequently deploys information stealers and remote access trojans (RATs) using techniques like hidden PowerShell and in-memory shellcode.

The BabaDeda service dates back to November 2021 when it targeted cryptocurrency and Web3 sectors. The loader identifies its host environment, avoids Russian and Belarusian systems, and checks for security products before injecting its payload into trusted Windows processes like ‘svchost.exe.’ This advanced malware can collect system data, browser artifacts, and execute commands, all while maintaining an encrypted connection to a command-and-control (C2) server.

Lorem Ipsum Loader Targets Compromised WordPress Sites

Another ClickFix campaign involves the Lorem Ipsum Loader, which utilizes compromised WordPress sites across various sectors to deliver its payload. This shift marks a departure from previous methods that used trojanized Microsoft Teams installers promoted through malvertising. The loader has been active since February 2026, adapting its delivery strategy following Microsoft’s disruption of a malware-signing service, Fox Tempest.

BlueVoyant researchers note that the new delivery mechanism involves downloading a ZIP file and an outdated Node.js version to execute JavaScript payloads. The Lorem Ipsum Loader retrieves further backdoor stages from C2 servers, facilitating the deployment of ransomware like Rhysida and BlackCat by the threat actor known as Vanilla Tempest.

Potemkin Loader and Its Advanced Capabilities

The Potemkin loader, part of a third sophisticated campaign, is deployed via an MSI package and an HTML Application (HTA) payload. This loader enables the execution of EtherRAT and RMMProject, which can control screens and steal browser credentials. Huntress researchers discovered Potemkin’s use of a domain generation algorithm for C2 communication, enhancing its resistance to detection.

The attackers conduct hands-on activities such as configuring Microsoft Defender exclusions and setting up network tunnels for persistent access. This campaign, like others, showcases the adaptability of threat actors in maintaining operations despite defensive efforts.

ClickFix remains a potent method for distributing malware, exploiting human behavior through deceptive instructions. Apple’s recent macOS update aims to mitigate these risks by alerting users to potentially harmful Terminal commands, underscoring the need for vigilance against evolving cyber threats.

The Hacker News Tags:BabaDeda Loader, ClickFix, cyber attacks, Cybersecurity, DLL side-loading, information stealer, JavaScript, Lorem Ipsum Loader, Malware, Node.js, Potemkin, PowerShell, Ransomware, social engineering, WordPress

Post navigation

Previous Post: Critical Vulnerabilities in FortiSandbox Under Exploitation
Next Post: Cal Water Probes Alleged Iranian Hacker Breach

Related Posts

Malicious Go, npm Packages Deliver Cross-Platform Malware, Trigger Remote Data Wipes Malicious Go, npm Packages Deliver Cross-Platform Malware, Trigger Remote Data Wipes The Hacker News
Fortinet SSL VPNs Hit by Global Brute-Force Wave Before Attackers Shift to FortiManager Fortinet SSL VPNs Hit by Global Brute-Force Wave Before Attackers Shift to FortiManager The Hacker News
AI Tools in Malware, Botnets, GDI Flaws, Election Attacks & More AI Tools in Malware, Botnets, GDI Flaws, Election Attacks & More The Hacker News
Chrome Extension Caught Injecting Hidden Solana Transfer Fees Into Raydium Swaps Chrome Extension Caught Injecting Hidden Solana Transfer Fees Into Raydium Swaps The Hacker News
Banking Malware Targets Windows and Android Devices Banking Malware Targets Windows and Android Devices The Hacker News
Ukrainian National Imprisoned for North Korea IT Fraud Ukrainian National Imprisoned for North Korea IT Fraud The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit Microsoft Teams to Mask Ransomware Traffic
  • Arch Linux Halts AUR Signups Amid Major Supply Chain Threat
  • Google Cloud Vertex AI SDK Flaw Exposed Model Uploads
  • Aembit Enhances IAM for Microsoft’s Copilot Studio
  • Cal Water Probes Alleged Iranian Hacker Breach

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit Microsoft Teams to Mask Ransomware Traffic
  • Arch Linux Halts AUR Signups Amid Major Supply Chain Threat
  • Google Cloud Vertex AI SDK Flaw Exposed Model Uploads
  • Aembit Enhances IAM for Microsoft’s Copilot Studio
  • Cal Water Probes Alleged Iranian Hacker Breach

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark