HomeSecurityNew ClickFix attacks infect systems with LummaStealer

New ClickFix attacks infect systems with LummaStealer

LummaStealer ,one of the most notorious infostealers , appears to be making a comeback, despite a major crackdown by law enforcement in early 2025. Its new resurgence demonstrates that the cybercrime ecosystem is adapting quickly, adopting more insidious techniques to bypass security and target unsuspecting users.

LummaStealer ClickFix

LummaStealer's latest activity no longer relies on classic distribution methods via exploit kits. Instead, attackers are turning to more aggressive and effective social engineering campaigns, exploiting human weakness as a key entry point.

See also: SSHStalker botnet compromises Linux machines via brute-force

LummaStealer: From exploit kits to social engineering campaigns

The most significant change in distribution tactics is the shift to “ClickFix” techniques , which use fake CAPTCHA verification pages . Users believe they are performing a simple security procedure, but in reality they are being led into a trap.

These deceptive messages convince victims to execute commands on their computer, often through copy and pasting code. This allows attackers to warnings operating system and install malware without having to directly download a suspicious file.

CastleLoader: The new "bridge" of contamination

At the same time, LummaStealer's delivery infrastructure has evolved significantly. Recent campaigns now use an advanced loader known as CastleLoader.

The role of the loader is crucial: it acts as an intermediate stage between the initial infection and the installation of the final payload. CastleLoader is designed to evade detection by antiviruses by executing malicious code directly in the system's memory.

New ClickFix attacks infect systems with LummaStealer

In this way, the attack leaves minimal traces on the hard drive, reducing the digital footprint and making forensic analysis difficult.

See also: Crazy ransomware: Abuse of legitimate employee monitoring tool

Bitdefender's research and hiding capabilities

Bitdefender analysts were among the first to spot this new activity. According to their research , CastleLoader is not just a transfer tool, but a complex system with powerful obfuscation and anti-analysis techniques.

The malware primarily targets Windows computers, collecting sensitive data such as:

  • browser credentials
  • active session cookies
  • cryptocurrency wallets
  • two-factor authentication (2FA) tokens

This information is then used for account takeovers, financial fraud, and identity theft on a global scale.

Technical Analysis: How CastleLoader Works

CastleLoader is often delivered as a compiled AutoIt script, a legitimate automation tool that is abused by attackers to hide their code.

After execution, it applies strong obfuscation: it replaces variables with random words and adds “dead code”, making it difficult to analyze by automated security systems.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Before downloading the final payload, it performs environment checks to determine whether it is on a real computer or in a researcher's sandbox. If it detects virtualization tools such as VMware or VirtualBox, it immediately stops its operation to avoid exposure.

See also: New 'ZeroDayRAT' kit allows complete compromise of iOS and Android devices

An interesting feature is that it creates a failed DNS lookup for a non-existent domain, leaving a unique “artifact” that defenders can leverage to detect an infection.

New ClickFix attacks infect systems with LummaStealer

Persistence and staying in the system

Once the environment is deemed safe, CastleLoader creates persistence by copying itself to the applications folder and creating a startup shortcut, so that it runs automatically on every reboot.

This means that the infection can remain active for a long time, collecting data without being noticed.

How can users be protected?

Experts warn that users should be especially wary of websites that request manual verification steps, such as copying and executing code.

Avoiding pirated software, keeping security systems , and being vigilant against suspicious CAPTCHAs are the most effective defenses against threats like LummaStealer, which continue to evolve and return more dangerous than ever.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS