A new series of ransomware attacks emerged in July 2025, leveraging malicious HTML (.HTA) files to silently install the Epsilon Red ransomware.
See also: Operation Checkmate: Seizure of pages of the BlackSuit ransomware group

The campaign, which has spread globally, masquerades as seemingly innocent verification pages branded “ClickFix,” attracting users visiting popular platforms such as Discord, Twitch, Kick , and OnlyFans.
Taking advantage of users’ trust in these services, attackers trick them into executing scripts delivered through the browser, bypassing conventional download warnings. The attack begins with a fake verification portal, which asks the user to “prove” their authenticity before accessing the content.
Once the button is clicked, the website redirects to a secondary page that is configured to run embedded ActiveX — an outdated, but still enabled Windows — allowing arbitrary command execution via Internet Explorer's rendering engine.
CloudSEK researchers pointed out that this redirection technique differs from the older Red ransomware deception methods, which relied on the use of the clipboard, resulting in the current version having a significantly higher infection success rate.
See also: Hackers target SharePoint servers with Warlock ransomware
After activating the ActiveX object, the malicious code calls the Windows Script Host (WSH) to create a hidden command shell.

From there, a PowerShell-like command downloads an executable binary from the attackers' infrastructure, executes it directly in memory, and leaves almost no visible trace during the initial phase of the breach.
CloudSEK analysts linked the hosting infrastructure to domains such as twtich[.]cc and capchabot[.]cc, as well as to the IP addresses 155.94.155.227 :2269 and 213.209.150.188 :8112, confirming the existence of a coherent network operated by the same cluster of malicious actors.
Victims undergo rapid encryption of their data, a hallmark of Red ransomware, with ransom notes resembling those of the infamous REvil gang, although with minor grammatical variations.
Beyond the file encryption itself, this technique exposes a deeper security hole: any environment where ActiveX remains active in older versions can be exploited to execute native binaries directly through the browser, bypassing mechanisms such as download quarantine, Microsoft SmartScreen, and most endpoint protection solutions
See also: CISA and FBI warn of increased Interlock ransomware attacks
Organizations that rely on online productivity suites or allow uncontrolled browser add-ons are at significantly increased risk.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: cybersecuritynews
