Tag: ClickFix Campaigns

ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures
News

ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures

According to independent reports from Morphisec, BlueVoyant, and Huntress, respectively, cybersecurity researchers have identified several ClickFix campaigns that distribute three malware loaders: BabaDeda Loader, Lorem Ipsum Loader, and Potemkin. Financial and educational institutions have been the target of BabaDeda Loader attacks since April 2026. In the past, BabaDeda activity was known to hide malicious payloads inside installer packages that appeared to be legitimate, according to Morphisec researcher Shmuel Uzan.The same code genome is preserved in this new framework, but it is expanded into a far more powerful loader designed for payload versatility, stealth, and evasion. The attacks begin with a ClickFix social engineering attack that trick users into executing PowerShel...