CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

ClickFix Removes Your Background but Leaves the Malware

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 702

As cited

Copy frozen at (site build).

threat intel

ClickFix Removes Your Background but Leaves the Malware

Huntress researchers identified BackgroundFix, a new social engineering variant of the ClickFix malware campaign that uses a fake Windows background removal tool to distribute CastleLoader, which then deploys NetSupport RAT and CastleStealer malware. The attack chain allows threat actors to gain remote access and steal sensitive data from compromised systems. This represents an evolution of the ClickFix tactics that have been exploited throughout 2024.

Why it matters: Organizations and end users are at risk of inadvertent malware installation through seemingly legitimate Windows utilities, leading to potential data theft and unauthorized remote access that could compromise credentials, intellectual property, and system integrity.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

ClickFix Removes Your Background but Leaves the Malware

Huntress researchers identified BackgroundFix, a variant of the ClickFix social engineering campaign that tricks users into removing their desktop background while delivering CastleLoader, NetSupport RAT, and CastleStealer malware. The tactic leverages a false background removal service to establish initial infection and enable remote access and credential theft.

Why it matters: Desktop users and IT teams managing Windows environments are at risk from this social engineering attack; practitioners should educate staff on ClickFix variants and monitor for CastleLoader and NetSupport RAT indicators.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary