Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Rundll32 and WebDAV: New ClickFix Variant Evades Detection

Rundll32 and WebDAV: New ClickFix Variant Evades Detection

Posted on March 30, 2026 By CWS

A sophisticated variant of the ClickFix attack technique is now targeting Windows users, utilizing rundll32.exe and WebDAV to bypass common security measures. This new approach deviates from older methods that relied on PowerShell or mshta, enhancing its ability to evade detection.

Innovative Attack Methods

Unlike previous versions, this variant leverages two integral Windows components, rundll32.exe and WebDAV, to discreetly deliver malicious payloads. This tactic evades many traditional security alerts, posing a greater threat, especially to organizations focused on script-based threat detection.

ClickFix attacks typically deceive users into executing harmful commands. In this instance, attackers masquerade a phishing website as a CAPTCHA verification page, persuading users to execute commands via the Windows Run dialog. The site, identified as “healthybyhillary[.]com,” misleads visitors into executing scripts that appear innocuous.

Detection Evasion Tactics

CyberProof analysts discovered this ClickFix variant during threat assessments, noting its reduced reliance on scripting engines. By using rundll32.exe with WebDAV, the attack accesses remote files over HTTP, loading malware from an attacker-controlled server. This method adds complexity, making it harder for security teams to identify the attack early.

The malware operates largely in memory, transitioning to PowerShell at a later stage. This later phase utilizes Invoke-Expression (IEX) to download further payloads without leaving a trace on disk, employing PowerShell flags to minimize noise.

Advanced Obfuscation Techniques

The core payload, SkimokKeep, is a secondary loader using advanced techniques to evade detection. Delivered as a Windows DLL, it avoids typical Windows API imports, instead employing a DJB2-style hashing algorithm to obscure its operations. This strategy complicates static analysis efforts.

To further evade detection, the malware checks for sandbox and virtual environments, employing anti-debugging measures. It also injects code into trusted processes like chrome.exe and msedge.exe, maintaining access while concealing its presence.

Security teams should monitor rundll32.exe executions involving davclnt.dll and DavSetCookie to identify WebDAV-based payload deliveries. Command-line auditing of LOLBins and restricting or monitoring WebDAV traffic is recommended. Blocking connections to known malicious IPs and domains, alongside enhancing user awareness about fake CAPTCHA threats, can fortify defenses.

For more updates, follow us on Google News, LinkedIn, and X. Set CSN as a preferred source in Google for instant updates.

Cyber Security News Tags:ClickFix, cyber attack, cyber defense, Cybersecurity, DLL injection, Malware, network security, online safety, Phishing, PowerShell, Rundll32, social engineering, threat detection, WebDAV, Windows security

Post navigation

Previous Post: OpenAI Resolves ChatGPT Data Breach and Codex Vulnerability
Next Post: TA446 Hackers Unleash DarkSword Kit on iOS Devices

Related Posts

New tool to Remove Copilot, Recall and Other AI tools From Windows 11 New tool to Remove Copilot, Recall and Other AI tools From Windows 11 Cyber Security News
Multiple Gitlab Security Vulnerabilities Let Attackers Trigger DoS Condition Multiple Gitlab Security Vulnerabilities Let Attackers Trigger DoS Condition Cyber Security News
Cost of a Breach Calculating ROI for Cybersecurity Investments Cost of a Breach Calculating ROI for Cybersecurity Investments Cyber Security News
SmartApeSG Campaign Leverages ClickFix Technique to Deploy NetSupport RAT SmartApeSG Campaign Leverages ClickFix Technique to Deploy NetSupport RAT Cyber Security News
Why Threat Prioritization Is the Key SOC Performance Driver   Why Threat Prioritization Is the Key SOC Performance Driver   Cyber Security News
DarkCloud Stealer Employs New Infection Chain and ConfuserEx-Based Obfuscation DarkCloud Stealer Employs New Infection Chain and ConfuserEx-Based Obfuscation Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • EvilTokens Phishing Exposes Finance Firms with ‘Ghost’ Code
  • Mustang Panda Exploits Cloud Service in Indian Cyber Attacks
  • WhatsApp Introduces Handles for Enhanced Privacy
  • Straiker Secures $64M to Enhance AI Security Solutions
  • WhatsApp Introduces Usernames for Enhanced Privacy

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • EvilTokens Phishing Exposes Finance Firms with ‘Ghost’ Code
  • Mustang Panda Exploits Cloud Service in Indian Cyber Attacks
  • WhatsApp Introduces Handles for Enhanced Privacy
  • Straiker Secures $64M to Enhance AI Security Solutions
  • WhatsApp Introduces Usernames for Enhanced Privacy

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark