Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
ClickFix Campaigns Enhance Malware Tactics with New Loaders

ClickFix Campaigns Enhance Malware Tactics with New Loaders

Posted on June 16, 2026 By CWS

Recent reports from cybersecurity firms Morphisec, BlueVoyant, and Huntress highlight advanced ClickFix campaigns deploying three new malware loaders: BabaDeda Loader, Lorem Ipsum Loader, and Potemkin. These campaigns are notable for their sophisticated methods of distribution and payload delivery.

Enhanced Malware Techniques with BabaDeda Loader

In April 2026, BabaDeda Loader attacks surfaced, targeting sectors such as education and finance. Initially discovered by Morphisec, BabaDeda Loader has evolved from hiding malicious content in legitimate installer packages to employing stealthier and more flexible delivery mechanisms. Attacks start with ClickFix social engineering attempts that trick victims into running PowerShell commands. The loader subsequently deploys information stealers and remote access trojans (RATs) using techniques like hidden PowerShell and in-memory shellcode.

The BabaDeda service dates back to November 2021 when it targeted cryptocurrency and Web3 sectors. The loader identifies its host environment, avoids Russian and Belarusian systems, and checks for security products before injecting its payload into trusted Windows processes like ‘svchost.exe.’ This advanced malware can collect system data, browser artifacts, and execute commands, all while maintaining an encrypted connection to a command-and-control (C2) server.

Lorem Ipsum Loader Targets Compromised WordPress Sites

Another ClickFix campaign involves the Lorem Ipsum Loader, which utilizes compromised WordPress sites across various sectors to deliver its payload. This shift marks a departure from previous methods that used trojanized Microsoft Teams installers promoted through malvertising. The loader has been active since February 2026, adapting its delivery strategy following Microsoft’s disruption of a malware-signing service, Fox Tempest.

BlueVoyant researchers note that the new delivery mechanism involves downloading a ZIP file and an outdated Node.js version to execute JavaScript payloads. The Lorem Ipsum Loader retrieves further backdoor stages from C2 servers, facilitating the deployment of ransomware like Rhysida and BlackCat by the threat actor known as Vanilla Tempest.

Potemkin Loader and Its Advanced Capabilities

The Potemkin loader, part of a third sophisticated campaign, is deployed via an MSI package and an HTML Application (HTA) payload. This loader enables the execution of EtherRAT and RMMProject, which can control screens and steal browser credentials. Huntress researchers discovered Potemkin’s use of a domain generation algorithm for C2 communication, enhancing its resistance to detection.

The attackers conduct hands-on activities such as configuring Microsoft Defender exclusions and setting up network tunnels for persistent access. This campaign, like others, showcases the adaptability of threat actors in maintaining operations despite defensive efforts.

ClickFix remains a potent method for distributing malware, exploiting human behavior through deceptive instructions. Apple’s recent macOS update aims to mitigate these risks by alerting users to potentially harmful Terminal commands, underscoring the need for vigilance against evolving cyber threats.

The Hacker News Tags:BabaDeda Loader, ClickFix, cyber attacks, Cybersecurity, DLL side-loading, information stealer, JavaScript, Lorem Ipsum Loader, Malware, Node.js, Potemkin, PowerShell, Ransomware, social engineering, WordPress

Post navigation

Previous Post: Critical Vulnerabilities in FortiSandbox Under Exploitation
Next Post: Cal Water Probes Alleged Iranian Hacker Breach

Related Posts

CISA Highlights Exploited Vulnerabilities in Key Software CISA Highlights Exploited Vulnerabilities in Key Software The Hacker News
CISA Adds Gladinet and CWP Flaws to KEV Catalog Amid Active Exploitation Evidence CISA Adds Gladinet and CWP Flaws to KEV Catalog Amid Active Exploitation Evidence The Hacker News
Meta Rolls Out New Tools to Protect WhatsApp and Messenger Users from Scams Meta Rolls Out New Tools to Protect WhatsApp and Messenger Users from Scams The Hacker News
DOJ Resentences BreachForums Founder to 3 Years for Cybercrime and Possession of CSAM DOJ Resentences BreachForums Founder to 3 Years for Cybercrime and Possession of CSAM The Hacker News
Critical n8n Vulnerability (CVSS 10.0) Allows Unauthenticated Attackers to Take Full Control Critical n8n Vulnerability (CVSS 10.0) Allows Unauthenticated Attackers to Take Full Control The Hacker News
Researchers Warn of Self-Spreading WhatsApp Malware Named SORVEPOTEL Researchers Warn of Self-Spreading WhatsApp Malware Named SORVEPOTEL The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical PAN-OS Flaw Leads to Qilin Ransomware Attacks
  • Microsoft’s KB5121767 Update Resolves Dell USB-C Issues
  • LG Monitor Software May Install Adware Silently
  • Microsoft to End OneDrive Sync Support for Windows 10
  • Paidwork Data Breach Exposes Millions of Users’ Data

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical PAN-OS Flaw Leads to Qilin Ransomware Attacks
  • Microsoft’s KB5121767 Update Resolves Dell USB-C Issues
  • LG Monitor Software May Install Adware Silently
  • Microsoft to End OneDrive Sync Support for Windows 10
  • Paidwork Data Breach Exposes Millions of Users’ Data

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark