HomeSecurityNew ClickFix attack imitates AnyDesk and distributes MetaStealer

New ClickFix attack imitates AnyDesk and distributes MetaStealer

A new variant of the ClickFix has emerged, mimicking a legitimate AnyDesk installer to spread the infostealer MetaStealer.

 ClickFix AnyDesk MetaStealer

This campaign exploits a fake Cloudflare Turnstile verification page to trick victims into executing a specially crafted Windows protocol handler, ultimately delivering a malicious MSI package disguised as a PDF.

As organizations continue to strengthen their defenses against traditional social engineering techniques, malicious actors are evolving their tactics, combining known traps with unexpected system componentsto evade detection and steal sensitive credentials.

In early August, users searching for the remote access AnyDesk encountered a misleading page at anydeesk[.]ink/download/anydesk.html. The page displayed what appeared to be a typical Cloudflare Turnstile prompt, with a “verify you are human” button.

See also: Palo Alto Networks confirms data breach

After clicking, victims were not prompted to paste a command into the Run dialog box, as in classic ClickFix attacks, but were instead redirected to Windows File Explorer via the search-ms URI handler. Huntress researchers noted that this small change in the redirect mechanism exploited the Windows Search protocol, which is not monitored as often, thus surprising security teams.

ClickFix: New variant of the attack

The infection chain unfolds when the search-ms URI calls a remote SMB share, delivering a Windows shortcut file named “Readme Anydesk.pdf.lnk” to the victim’s system. Unlike FileFix variants that rely on PowerShell commands pasted to the clipboard, this attack automatically launches the LNK payload, which in turn executes a script to download and install two components: the genuine AnyDesk installer hosted in Microsoft Edge and a deceptive PDF.

The deceptive file is actually an MSI package that dynamically embeds the victim's computer name in its download URL, using the environment variable %COMPUTERNAME%. Once downloaded, the MSI is installed via a command that reveals two main artifacts: a CustomActionDLL responsible for orchestrating the installation, and a CAB archive containing ls26.exe, the MetaStealer dropper , and cleanup scripts.

New ClickFix attack imitates AnyDesk and distributes MetaStealer

Huntress analysts identified ls26.exe as being protected by Private EXE Protector and exhibiting typical MetaStealer behaviors, including collecting browser credentials and stealing crypto wallets.

See also: Ukrainian FDN3 Network Launches Massive Brute-Force Attacks

At the heart of this campaign is the clever use of Windows Search. Using the search-ms URI protocol, attackers bypass the limitations of the Run window in fortified environments and inject payloads directly through File Explorer.

Once the user confirms the File Explorer prompt, the LNK file silently executes the download routines. The MSI's CustomActionDLL then triggers the retrieval of Binary.bz.WrappedSetupProgram, which unpacks ls26.exe and 1.js. The JavaScript file ensures the removal of intermediate files, while ls26.exe starts the data extraction phase.

By abusing legitimate Windows protocols and file handling, this attack evades sandbox detection and security alerts until the final payload unleashes its malicious logic. This emerging tactic highlights the importance of monitoring unconventional extensions of trusted system features.

New ClickFix attack imitates AnyDesk and distributes MetaStealer

Defenders should consider implementing strict protocol handler policies, SMB auditing, and contextual analysis of MSI installations to detect and disrupt these sophisticated social engineering campaigns.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Lazarus hackers deploy three RATs on compromised systems

The new ClickFix variant incident highlights how quickly the cybercrime landscape. The attackers’ innovation lies not only in the malware they distribute, but also in the way they exploit everyday operating system tools. This raises a troubling question for broader security: how many more “innocent” features can be exploited in a similar way?

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS