CyberSecurityBoardThreat Intel · CVEs · Products
Malware

ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures

June 25, 2026

Cybersecurity researchers have identified multiple ClickFix campaigns deploying three new malware loaders: BabaDeda Loader, Lorem Ipsum Loader, and Potemkin. These campaigns use social engineering to trick users into running PowerShell commands, leading to the delivery of information stealers and remote access trojans (RATs).

BabaDeda Loader, observed in April 2026, targets education and financial sectors. It uses hidden PowerShell, in-memory shellcode, DLL side-loading, and external payload storage to drop malware like DanaBot and SectopRAT. The loader avoids Russian and Belarusian systems and performs security product checks before injecting payloads into trusted Windows processes.

Lorem Ipsum Loader, active since February 2026, is delivered via compromised WordPress sites using fake Edge browser update lures. It downloads a ZIP file and an outdated Node.js version to execute JavaScript payloads. The loader is attributed to the financially motivated threat actor Vanilla Tempest (aka Rapid Brigantine, Vice Society) and culminates in Rhysida ransomware deployment.

Potemkin Loader uses a domain generation algorithm (DGA) to find its command-and-control (C2) server and reflectively loads modules like EtherRAT and RMMProject. RMMProject bypasses Chromium’s App-Bound Encryption to steal browser credentials. The campaign involves hands-on keyboard activity, including lateral movement via WMIExec and SMBExec.

ClickFix remains an effective technique due to its exploitation of human nature, prompting Apple to introduce a security pop-up in macOS Tahoe 26.4 to warn users about pasting commands into Terminal.

CVEs: CVE-2026-11645

Attack groups: Vanilla Tempest, Rapid Brigantine, Vice Society, Fox Tempest, Forging Marauder

Malware: BabaDeda Loader, Lorem Ipsum Loader, Potemkin, DanaBot, SectopRAT, EtherRAT, RMMProject, LockBit, Rhysida, BlackCat, Zeppelin, Quantum Locker

Companies: Morphisec, BlueVoyant, Huntress, Microsoft, Apple, Cloudflare

Products: Microsoft Defender, Chisel, Cloudflare tunnel, WMIExec, SMBExec, Node.js