Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
ClickFix Campaigns Enhance Malware Tactics with New Loaders

ClickFix Campaigns Enhance Malware Tactics with New Loaders

Posted on June 16, 2026 By CWS

Recent reports from cybersecurity firms Morphisec, BlueVoyant, and Huntress highlight advanced ClickFix campaigns deploying three new malware loaders: BabaDeda Loader, Lorem Ipsum Loader, and Potemkin. These campaigns are notable for their sophisticated methods of distribution and payload delivery.

Enhanced Malware Techniques with BabaDeda Loader

In April 2026, BabaDeda Loader attacks surfaced, targeting sectors such as education and finance. Initially discovered by Morphisec, BabaDeda Loader has evolved from hiding malicious content in legitimate installer packages to employing stealthier and more flexible delivery mechanisms. Attacks start with ClickFix social engineering attempts that trick victims into running PowerShell commands. The loader subsequently deploys information stealers and remote access trojans (RATs) using techniques like hidden PowerShell and in-memory shellcode.

The BabaDeda service dates back to November 2021 when it targeted cryptocurrency and Web3 sectors. The loader identifies its host environment, avoids Russian and Belarusian systems, and checks for security products before injecting its payload into trusted Windows processes like ‘svchost.exe.’ This advanced malware can collect system data, browser artifacts, and execute commands, all while maintaining an encrypted connection to a command-and-control (C2) server.

Lorem Ipsum Loader Targets Compromised WordPress Sites

Another ClickFix campaign involves the Lorem Ipsum Loader, which utilizes compromised WordPress sites across various sectors to deliver its payload. This shift marks a departure from previous methods that used trojanized Microsoft Teams installers promoted through malvertising. The loader has been active since February 2026, adapting its delivery strategy following Microsoft’s disruption of a malware-signing service, Fox Tempest.

BlueVoyant researchers note that the new delivery mechanism involves downloading a ZIP file and an outdated Node.js version to execute JavaScript payloads. The Lorem Ipsum Loader retrieves further backdoor stages from C2 servers, facilitating the deployment of ransomware like Rhysida and BlackCat by the threat actor known as Vanilla Tempest.

Potemkin Loader and Its Advanced Capabilities

The Potemkin loader, part of a third sophisticated campaign, is deployed via an MSI package and an HTML Application (HTA) payload. This loader enables the execution of EtherRAT and RMMProject, which can control screens and steal browser credentials. Huntress researchers discovered Potemkin’s use of a domain generation algorithm for C2 communication, enhancing its resistance to detection.

The attackers conduct hands-on activities such as configuring Microsoft Defender exclusions and setting up network tunnels for persistent access. This campaign, like others, showcases the adaptability of threat actors in maintaining operations despite defensive efforts.

ClickFix remains a potent method for distributing malware, exploiting human behavior through deceptive instructions. Apple’s recent macOS update aims to mitigate these risks by alerting users to potentially harmful Terminal commands, underscoring the need for vigilance against evolving cyber threats.

The Hacker News Tags:BabaDeda Loader, ClickFix, cyber attacks, Cybersecurity, DLL side-loading, information stealer, JavaScript, Lorem Ipsum Loader, Malware, Node.js, Potemkin, PowerShell, Ransomware, social engineering, WordPress

Post navigation

Previous Post: Critical Vulnerabilities in FortiSandbox Under Exploitation
Next Post: Cal Water Probes Alleged Iranian Hacker Breach

Related Posts

Firewall Exploits, AI Data Theft, Android Hacks, APT Attacks, Insider Leaks & More Firewall Exploits, AI Data Theft, Android Hacks, APT Attacks, Insider Leaks & More The Hacker News
Samsung Fixes Critical Zero-Day CVE-2025-21043 Exploited in Android Attacks Samsung Fixes Critical Zero-Day CVE-2025-21043 Exploited in Android Attacks The Hacker News
The New JavaScript Injection Playbook The New JavaScript Injection Playbook The Hacker News
A New Security Layer for macOS Takes Aim at Admin Errors Before Hackers Do A New Security Layer for macOS Takes Aim at Admin Errors Before Hackers Do The Hacker News
CISA Urges Patching of Apple and CMS Vulnerabilities CISA Urges Patching of Apple and CMS Vulnerabilities The Hacker News
Two New Supermicro BMC Bugs Allow Malicious Firmware to Evade Root of Trust Security Two New Supermicro BMC Bugs Allow Malicious Firmware to Evade Root of Trust Security The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Brinks Home Confirms Major Data Breach Amid Hacker Claims
  • Flaw in Coldcard Wallet Triggers $70 Million Bitcoin Heist
  • Top Web Application Firewalls for 2026: Expert Ranking
  • Top DNS Security Solutions for 2026
  • Windows 11 Enhances Taskbar and AI Features

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Brinks Home Confirms Major Data Breach Amid Hacker Claims
  • Flaw in Coldcard Wallet Triggers $70 Million Bitcoin Heist
  • Top Web Application Firewalls for 2026: Expert Ranking
  • Top DNS Security Solutions for 2026
  • Windows 11 Enhances Taskbar and AI Features

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark