HomeSecurityClickFix Campaigns Expand Malware Distribution with New Loaders and Fake...

ClickFix Campaigns Expand Malware Distribution with New Loaders and Fake Updates

Cybersecurity researchers have identified multiple ClickFix campaigns delivering three malware loaders, known as BabaDeda Loader, Lorem Ipsum Loader , and Potemkin, according to independent reports from Morphisec, BlueVoyant , and Huntress.

See also: ClickFix techniques used in new infostealer campaigns

ClickFix Campaigns Expand Malware Distribution with New Loaders and Fake Updates

Attacks involving the BabaDeda Loader, observed in April 2026, have targeted educational and financial institutions. Morphisecresearcher Shmuel Uzannoted that BabaDeda's previous activity was known for hiding malicious payloads inside legitimate-looking installation packages. This new framework retains the same code genome but expands it into a more capable loader designed for payload concealment, evasion, and flexibility.

The attacks begin with a social engineering tactic called ClickFix, which tricks users into executing PowerShell commands provided by the attackers to deliver the loader. This loader is then used to drop infostealers and remote access trojans (RATs) using a combination of techniques such as hidden PowerShell, in-memory shellcode, DLL side-loading, and external payload storage.

The activity has been attributed to BabaDeda, a crypto service first documented by Morphisec in November 2021, which was linked to a campaign targeting the cryptocurrency and Web3 sectors to distribute infostealers, RATs, and the LockBit ransomware.

The loader is designed to control the host system, avoid execution on systems in Russia or Belarus, and perform checks related to security products before retrieving the main payload and injecting it into a trusted Windows process such as “svchost.exe.”

One of the malware families delivered via the BabaDeda Loader is a .NET backdoor and infostealer that can collect sensitive data and establish an encrypted channel to a command and control (C2) server. The malware supports a wide range of functions, including:

See also: Velvet Tempest: Distribution of DonutLoader and CastleRAT via ClickFix techniques

ClickFix Campaigns Expand Malware Distribution with New Loaders and Fake Updates
  • Collect detailed system information
  • Discovering installed browser profiles
  • Export browser objects such as cookies, browsing history, saved credentials, preferences, and local state encryption keys
  • Traversing directories and selecting files based on configurable rules
  • Reading and extracting file contents
  • Take screenshots and display information
  • Execute shell commands or external procedures and collect output
  • Transfer data back to the C2 server
  • Use native Windows APIs for interaction with processes, memory operations, DPAPI access, Restart Manager behavior, and advanced file access

A second attack chain drops a ZIP file that uses DLL side-loading to launch DanaBot and SectopRAT (also known as ArechClient). Importantly, these attacks use a staged loader component called Storage Crypter that reads payload material from external storage such as “List.Control.dat” files.

The visible application package appears legitimate, while the malicious payloads remain hidden within externally stored containers and are decoded just before execution. This design minimizes forensic visibility, complicates automated analysis, and reduces the opportunities for traditional security tools to detect malicious activity before execution.

The findings represent an evolution of modern shipper frameworks, which have become increasingly modular, separating delivery, storage, execution, and cargo deployment into discrete components rather than relying on a single entity.

See also: ClickFix attack distributes StealC malware to Windows systems

ClickFix Campaigns Expand Malware Distribution with New Loaders and Fake Updates

The ClickFix technique has also been observed in an active campaign that uses at least five compromised WordPress sites as a launching point to deliver a new loader and backdoor coded Lorem Ipsum Loader. The compromised sites span multiple sectors, including architecture, legal services, and construction technology. These attacks mark a departure from previous opportunistic campaigns that used modified Microsoft Teams installers via fake download portals promoted through SEO poisoning and malicious advertising.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS