IOC Radar
TLP:WHITE3 IOCs

New ClickFix Campaign Delivers MLTBackdoor Malware in Multi-Stage Attacks

CP
Cyber Press
Published June 10, 2026Original Report

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYunknownINFRASTRUCTUREunknownCAPABILITYCobalt StrikeVICTIMunknown
Adversary
Infrastructure
Capability(1)
Victim

Attack Flow8 steps · MITRE ATT&CK mapped

Initial AccessTA0001·T1566
1/8
Phishing
ActionTrick user into running script
Attackers use deceptive social engineering (ClickFix) via automotive-themed web pages to trick victims into executing a malicious script.

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise3

TypeIndicatorConfidenceScoreFirst Seen
SHA25646b2155c1e71b840d4b7a2e94410b89a61e2446523e6f497206d402eb02e0e93
file-hashintel-blogloader
Medium
53
Jun 10, 26
SHA2569e52cc90cff150abe21f0a6440e86e0a99ff383b81061b96def8948e21d0ac66
file-hashintel-blogmalware
Medium
53
Jun 10, 26
SHA2561e41c7bfaa6aa3b93b6cc024274a10e33f3e12fe7c98c1db387ef8927f9d1984
file-hashintel-blogloader
Medium
53
Jun 10, 26

IOC Relationship Graph

IOC Relationship Graph3 total IOCs
SHA256
SHA2563Malware1REPORTNew ClickFix Campaign DeliCobalt Strike
scroll to zoom · drag to pan · click IOC to open