Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
ClickFix Campaigns Enhance Malware Tactics with New Loaders

ClickFix Campaigns Enhance Malware Tactics with New Loaders

Posted on June 16, 2026 By CWS

Recent reports from cybersecurity firms Morphisec, BlueVoyant, and Huntress highlight advanced ClickFix campaigns deploying three new malware loaders: BabaDeda Loader, Lorem Ipsum Loader, and Potemkin. These campaigns are notable for their sophisticated methods of distribution and payload delivery.

Enhanced Malware Techniques with BabaDeda Loader

In April 2026, BabaDeda Loader attacks surfaced, targeting sectors such as education and finance. Initially discovered by Morphisec, BabaDeda Loader has evolved from hiding malicious content in legitimate installer packages to employing stealthier and more flexible delivery mechanisms. Attacks start with ClickFix social engineering attempts that trick victims into running PowerShell commands. The loader subsequently deploys information stealers and remote access trojans (RATs) using techniques like hidden PowerShell and in-memory shellcode.

The BabaDeda service dates back to November 2021 when it targeted cryptocurrency and Web3 sectors. The loader identifies its host environment, avoids Russian and Belarusian systems, and checks for security products before injecting its payload into trusted Windows processes like ‘svchost.exe.’ This advanced malware can collect system data, browser artifacts, and execute commands, all while maintaining an encrypted connection to a command-and-control (C2) server.

Lorem Ipsum Loader Targets Compromised WordPress Sites

Another ClickFix campaign involves the Lorem Ipsum Loader, which utilizes compromised WordPress sites across various sectors to deliver its payload. This shift marks a departure from previous methods that used trojanized Microsoft Teams installers promoted through malvertising. The loader has been active since February 2026, adapting its delivery strategy following Microsoft’s disruption of a malware-signing service, Fox Tempest.

BlueVoyant researchers note that the new delivery mechanism involves downloading a ZIP file and an outdated Node.js version to execute JavaScript payloads. The Lorem Ipsum Loader retrieves further backdoor stages from C2 servers, facilitating the deployment of ransomware like Rhysida and BlackCat by the threat actor known as Vanilla Tempest.

Potemkin Loader and Its Advanced Capabilities

The Potemkin loader, part of a third sophisticated campaign, is deployed via an MSI package and an HTML Application (HTA) payload. This loader enables the execution of EtherRAT and RMMProject, which can control screens and steal browser credentials. Huntress researchers discovered Potemkin’s use of a domain generation algorithm for C2 communication, enhancing its resistance to detection.

The attackers conduct hands-on activities such as configuring Microsoft Defender exclusions and setting up network tunnels for persistent access. This campaign, like others, showcases the adaptability of threat actors in maintaining operations despite defensive efforts.

ClickFix remains a potent method for distributing malware, exploiting human behavior through deceptive instructions. Apple’s recent macOS update aims to mitigate these risks by alerting users to potentially harmful Terminal commands, underscoring the need for vigilance against evolving cyber threats.

The Hacker News Tags:BabaDeda Loader, ClickFix, cyber attacks, Cybersecurity, DLL side-loading, information stealer, JavaScript, Lorem Ipsum Loader, Malware, Node.js, Potemkin, PowerShell, Ransomware, social engineering, WordPress

Post navigation

Previous Post: Critical Vulnerabilities in FortiSandbox Under Exploitation
Next Post: Cal Water Probes Alleged Iranian Hacker Breach

Related Posts

Cyber Espionage Threatens Asian Infrastructure via Web Exploits Cyber Espionage Threatens Asian Infrastructure via Web Exploits The Hacker News
PyPI Warns of Ongoing Phishing Campaign Using Fake Verification Emails and Lookalike Domain PyPI Warns of Ongoing Phishing Campaign Using Fake Verification Emails and Lookalike Domain The Hacker News
Newly Emerged GLOBAL GROUP RaaS Expands Operations with AI-Driven Negotiation Tools Newly Emerged GLOBAL GROUP RaaS Expands Operations with AI-Driven Negotiation Tools The Hacker News
Xinbi Telegram Market Tied to .4B in Crypto Crime, Romance Scams, North Korea Laundering Xinbi Telegram Market Tied to $8.4B in Crypto Crime, Romance Scams, North Korea Laundering The Hacker News
New Albiriox MaaS Malware Targets 400+ Apps for On-Device Fraud and Screen Control New Albiriox MaaS Malware Targets 400+ Apps for On-Device Fraud and Screen Control The Hacker News
Lithuania Strengthens Cybersecurity Against AI Fraud Lithuania Strengthens Cybersecurity Against AI Fraud The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical cPanel Security Flaw in LiteSpeed Server Fixed
  • Homebrew 7.0.0 Unveils Vulnerability Scanner and Enhanced Security
  • Major Breach at Japan’s Digital Agency Exposes 240,000 Records
  • Critical Cisco Email Gateway Flaw Exploited, CISA Warns
  • Underground AI Service ‘Luciferus’ Promoted by Hackers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical cPanel Security Flaw in LiteSpeed Server Fixed
  • Homebrew 7.0.0 Unveils Vulnerability Scanner and Enhanced Security
  • Major Breach at Japan’s Digital Agency Exposes 240,000 Records
  • Critical Cisco Email Gateway Flaw Exploited, CISA Warns
  • Underground AI Service ‘Luciferus’ Promoted by Hackers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark