Verticals Targeted: Government, Financial Services, Education, Transportation, Cryptocurrency, Enterprise Environments
Regions Targeted: North America, Europe, Middle East
The Evolution of ClickFix: Mapping the Growing *Fix Family
Aug 24, 2026, 3:34:35 PM / by The Hivemind posted in Threat Bulletin, ClickFix, FileFix, PowerShell attacks, prompt injection, Windows Run
ClickFix-Themed Campaign Deploys Starland RAT and WLDR Framework
Aug 3, 2026, 1:59:52 PM / by The Hivemind posted in Threat Bulletin, Remcos RAT, ClickFix, UAT-11795, Cisco Talos, Starland RAT, WLDR, WLDR PowerShell, CastleStealer, Trojanized installers
Verticals Targeted: Cryptocurrency
Regions Targeted: United States, Germany, Romania, Venezuela
Related Families: Starland RAT, WLDR Framework, Remcos RAT, CastleStealer
Executive Summary
Industry researchers identified a financially motivated, Russian-speaking threat actor tracked as UAT-11795 conducting a sophisticated malware campaign targeting users primarily in the United States since at least June 2025. The operation employs suspected ClickFix-style social engineering, trojanized software installers, and a custom Python-based remote access tool, Starland RAT, to establish persistent access and deploy additional malware, including the previously undocumented WLDR PowerShell framework, CastleStealer, and Remcos RAT. The campaign demonstrates a modular architecture, resilient C2 infrastructure, and a strong emphasis on credential theft, cryptocurrency wallet harvesting, and long-term post-compromise access.
CastleLoader
Aug 8, 2025, 11:51:37 AM / by The Hivemind posted in Threat Bulletin, Phishing, Redline, Emerging Threat, PowerShell, StealC, ClickFix, CastleLoader, GitHub, DeerStealer, malware loader, NetSupport RAT
Verticals Targeted: Government
Regions Targeted: US
Related Families: StealC, RedLine, NetSupport RAT, DeerStealer, HijackLoader, SectopRAT
Executive Summary
CastleLoader, a versatile malware loader, has infected 469 devices since May 2025, leveraging Cloudflare-themed ClickFix phishing and fake GitHub repositories to deliver information stealers and RATs. Its sophisticated attack chain, high infection rate, and modular design make it a significant threat to organizations, particularly U.S. government entities.
EDDIESTEALER
Jun 9, 2025, 12:29:15 PM / by The Hivemind posted in Threat Bulletin, Infostealer, Data Theft, social engineering, Emerging Threat, EDDIESTEALER, Rust Malware, CAPTCHA Campaign, ClickFix, PowerShell Attack, ChromeKatz, Cybersecurity
Verticals Targeted: Not specified
Regions Targeted: Not specified
Related Families: None