Velvet Tempest ClickFix malvertising campaign
Campaign
Summary
Hide ▲
Show ▼
Velvet Tempest ran a malvertising-driven ClickFix operation that used obfuscated Windows commands to gain access and stage payloads, making the intrusion chain more effective and more visible as an active adversary campaign. The activity was observed over February 3-16 and showed hands-on operator tradecraft against a U.S. nonprofit-like environment with more than 3,000 endpoints and 2,500 users.
Related Happenings
Ministry of Justice and Legal Affairs of Oman hit by network compromise
Incident
H score37
First: 06.05.2026 16:00
Last: 06.05.2026 16:00
Sources 1
About this happening:
The Ministry of Justice and Legal Affairs of Oman suffered an active intrusion that exposed session logs and more than 26,000 user records, raising risk to judicia...
Ministry of Justice and Legal Affairs of Oman hit by network compromise
IncidentAbout this happening: The Ministry of Justice and Legal Affairs of Oman suffered an active intrusion that exposed session logs and more than 26,000 user records, raising risk to judicia...
Storm-1175 high-velocity zero-day and N-day intrusion campaign
Campaign
H score44
First: 07.04.2026 09:35
Last: 07.04.2026 09:35
Sources 1
About this happening:
Storm-1175 is running a high-velocity intrusion campaign that chains zero-day and N-day vulnerabilities to gain initial access to exposed systems, raising the risk...
Storm-1175 high-velocity zero-day and N-day intrusion campaign
CampaignAbout this happening: Storm-1175 is running a high-velocity intrusion campaign that chains zero-day and N-day vulnerabilities to gain initial access to exposed systems, raising the risk...
ClickFix MacSync social-engineering campaign targeting macOS users
Campaign
H score38
First: 16.03.2026 13:41
Last: 16.03.2026 13:41
Sources 1
About this happening:
ClickFix campaigns continued to blend fake verification pages with command-pasting lures, including a 2025-11-06 wave that used embedded video tutorials, automatic O...
ClickFix MacSync social-engineering campaign targeting macOS users
CampaignAbout this happening: ClickFix campaigns continued to blend fake verification pages with command-pasting lures, including a 2025-11-06 wave that used embedded video tutorials, automatic O...
Hive0163 extortion and ransomware campaign using ClickFix and malvertising
Campaign
H score35
First: 12.03.2026 19:02
Last: 12.03.2026 19:02
Sources 1
About this happening:
Hive0163 is running an active extortion and ransomware campaign that expands access and raises the risk of large-scale data exfiltration. The operation uses ClickFix,...
Hive0163 extortion and ransomware campaign using ClickFix and malvertising
CampaignAbout this happening: Hive0163 is running an active extortion and ransomware campaign that expands access and raises the risk of large-scale data exfiltration. The operation uses ClickFix,...
Transparent Tribe AI-assisted implant campaign targeting India
Campaign
H score32
First: 06.03.2026 17:11
Last: 06.03.2026 17:11
Sources 1
About this happening:
Transparent Tribe (APT36) is using AI-powered coding tools to mass-produce disposable implants in an active campaign targeting the Indian government, its embassies...
Transparent Tribe AI-assisted implant campaign targeting India
CampaignAbout this happening: Transparent Tribe (APT36) is using AI-powered coding tools to mass-produce disposable implants in an active campaign targeting the Indian government, its embassies...
Timeline
-
07.03.2026 18:14 2 articles · 4mo ago
Velvet Tempest ClickFix malvertising campaign disclosed
Initial DisclosureMalBeacon disclosed that Velvet Tempest, also tracked as DEV-0504, used a malvertising-driven ClickFix chain with obfuscated Windows Run dialog commands, nested cmd.exe activity, finger.exe retrieval, PowerShell downloads, csc.exe compilation, and Python-based persistence to stage DonutLoader and CastleRAT against a U.S. nonprofit-like environment with more than 3,000 endpoints and over 2,500 users. The observed activity covered February 3-16 and included hands-on keyboard reconnaissance, host discovery, environment profiling, and Chrome credential harvesting, while Termite ransomware was not deployed in the intrusion.
Show sources
- Termite ransomware breaches linked to ClickFix CastleRAT attacks — www.bleepingcomputer.com — 07.03.2026 18:14
- Termite ransomware breaches linked to ClickFix CastleRAT attacks — www.bleepingcomputer.com — 07.03.2026 18:14